You can enable or disable the Evidence Collector module to collect logs generated by the Trellix appliance using the Web UI or CLI:
When you enable the Evidence Collector module on the appliance, the appliance sends the network event logs to Helix in the AWS endpoint that you specified for further analysis. When you disable the Evidence Collector module on the appliance, the appliance does not send the network event logs to Helix in the AWS endpoint.
Caution
When the Evidence Collector module is enabled on the Network Security 4400 appliance models and above, peak throughput may be degraded by 10% to 15%.
When the Evidence Collector module is enabled on the Network Security 2500 appliance models and below, peak throughput may be degraded by 15% to 20%.
Note
Before you enable the Evidence Collector module, you must specify a valid hostname for the VPC within an AWS endpoint.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix