Use the CLI commands in this topic to enable or disable the Layer 7 Metadata Event Exporter to collect logs generated by the Trellix appliance.
Go to CLI configuration mode.
hostname > enablehostname # configure terminalSpecify the protocol to send Layer 7 metadata events to the Splunk Enterprise server.
To send Layer 7 metadata events over UDP:
hostname (config) # l7metadata-export protocol udp
To send Layer 7 metadata events over TCP:
hostname (config) # l7metadata-export protocol tcp
To send Layer 7 metadata events over HTTPS:
hostname (config) # l7metadata-export protocol https
Specify the destination IPv4/IPv6 address of the Splunk Enterprise server.
hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress>
where
<IPAddress>is the destination IPv4/IPv6 address of the Splunk Enterprise server.Specify the port that the appliance can use to initiate a connection with the Splunk Enterprise server.
hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress> port <portNumber>
where
<portNumber>is the port that the appliance uses to initiate a connection. Valid values are integers ranging from 514 to 65535.Specify the authorization header that is used to create the HTTPS event collector token on the Splunk Enterprise server.
hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress> port <portNumber> authorization-header <authorization-header>
where
<authorization-header>is the authorization header that is used to create the HTTPS event collector token.Note
The HTTPS Event Collector (HEC) token is the Splunk authorization header.
Enable the Layer 7 Metadata Event Exporter on the appliance.
hostname (config) # l7metadata-export enable
If the Layer 7 Metadata Event Exporter is enabled, the following message appears:
Enabling l7metadata-export
Verify the status of the Layer 7 Metadata Event Exporter.
hostname (config) # show l7metadata-export status l7metadata-export status State: Enable Running Status: Running Platform support: Supported
Save your changes.
hostname (config)# write memory
Go to CLI configuration mode.
hostname > enablehostname # configure terminalDisable the Layer 7 Metadata Event Exporter on the appliance.
hostname (config) # no l7metadata-export enable
Verify the status of the Layer 7 Metadata Event Exporter.
hostname (config) # show l7metadata-export status l7metadata-export status State: Disable Running Status: Not Running Platform support: Supported
Save your changes.
hostname (config)# write memory