The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the Communications Broker Sender

Prev Next

You can enable or disable the Communications Broker Sender (Comm Broker) by using the Network Security appliance Web UI or CLI:

When Comm Broker is enabled, Comm Broker can receive and send third-party logs to Helix Enterprise for analysis on the Network Security appliance. When Comm Broker is disabled, Comm Broker cannot receive and send third-party logs to Helix Enterprise on the appliance.

Note

Comm Broker is disabled by default.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Configure a valid hostname for the VPC within an AWS endpoint ( Helix Enterprise URL)

Note

To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance. See Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint using the CLI.

You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.