The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the layer 7 metadata Event Exporter

Prev Next

You can enable or disable the Layer 7 Metadata Event Exporter to collect logs generated by the Network Security appliance using the appliance Web UI or CLI:

When you enable the Layer 7 Metadata Event Exporter on the appliance, the appliance sends the network event logs to the Splunk Enterprise server for further analysis. When you disable the Layer 7 Metadata Event Exporter on the appliance, the appliance will not send the network event logs to the Splunk Enterprise server. The Layer 7 Metadata Event Exporter is disabled by default and must be configured and enabled.

Prerequisites