The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the Evidence Collector module

Prev Next

You can enable or disable the Evidence Collector module to collect logs generated by the Trellix appliance using the Web UI or CLI:

When you enable the Evidence Collector module on the appliance, the appliance sends the network event logs to Helix in the AWS endpoint that you specified for further analysis. When you disable the Evidence Collector module on the appliance, the appliance does not send the network event logs to Helix in the AWS endpoint.

Caution

When the Evidence Collector module is enabled on the Network Security 4400 appliance models and above, peak throughput may be degraded by 10% to 15%.

When the Evidence Collector module is enabled on the Network Security 2500 appliance models and below, peak throughput may be degraded by 15% to 20%.

Note

Before you enable the Evidence Collector module, you must specify a valid hostname for the VPC within an AWS endpoint.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix