The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the Evidence Collector module using the CLI

Prev Next

Use the CLI commands in this topic to enable or disable the Evidence Collector module using the CLI.

To enable the Evidence Collector module:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable the Evidence Collector module on the appliance.

    hostname (config) # tapsender enable

    If the Evidence Collector module is enabled, the following message appears:

    Enable tapsender
    Changes might take a few seconds to take effect.
    Use the CLI show tapsender status to check the status.
  3. Verify the status of the Evidence Collector module.

    hostname (config) # show tapsender status
    Tapsender status
      State:                            Enabled
      Platform support:                 Supported
To disable the Evidence Collector module:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable the Evidence Collector module on the appliance.

    hostname (config) # no tapsender enable

    If the Evidence Collector module is disabled, the following message appears:

    Disable tapsender
  3. Verify the status of the Evidence Collector module.

    hostname (config) # show tapsender status
    Tapsender status
       State:                            Disabled
       Platform support:                 Supported