The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or Disabling the layer 7 metadata Event Exporter using the CLI

Prev Next

Use the CLI commands in this topic to enable or disable the Layer 7 Metadata Event Exporter to collect logs generated by the Trellix appliance.

To enable the Layer 7 Metadata Event Exporter:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Specify the protocol to send Layer 7 metadata events to the Splunk Enterprise server.

    • To send Layer 7 metadata events over UDP:

      hostname (config) # l7metadata-export protocol udp
    • To send Layer 7 metadata events over TCP:

      hostname (config) # l7metadata-export protocol tcp
    • To send Layer 7 metadata events over HTTPS:

      hostname (config) # l7metadata-export protocol https
  3. Specify the destination IPv4/IPv6 address of the Splunk Enterprise server.

    hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress>

    where <IPAddress> is the destination IPv4/IPv6 address of the Splunk Enterprise server.

  4. Specify the port that the appliance can use to initiate a connection with the Splunk Enterprise server.

    hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress> port <portNumber>

    where <portNumber> is the port that the appliance uses to initiate a connection. Valid values are integers ranging from 514 to 65535.

  5. Specify the authorization header that is used to create the HTTPS event collector token on the Splunk Enterprise server.

    hostname (config) # l7metadata-export protocol <protocolType> ip <IPAddress> port <portNumber> authorization-header <authorization-header>

    where <authorization-header> is the authorization header that is used to create the HTTPS event collector token.

    Note

    The HTTPS Event Collector (HEC) token is the Splunk authorization header.

  6. Enable the Layer 7 Metadata Event Exporter on the appliance.

    hostname (config) # l7metadata-export enable

    If the Layer 7 Metadata Event Exporter is enabled, the following message appears:

    Enabling l7metadata-export
  7. Verify the status of the Layer 7 Metadata Event Exporter.

    hostname (config) # show l7metadata-export status
    l7metadata-export status
            State:    Enable
            Running Status:    Running
            Platform support:    Supported
  8. Save your changes.

    hostname (config)# write memory
To disable the Layer 7 Metadata Event Exporter:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Disable the Layer 7 Metadata Event Exporter on the appliance.

    hostname (config) # no l7metadata-export enable
  3. Verify the status of the Layer 7 Metadata Event Exporter.

    hostname (config) # show l7metadata-export status
    l7metadata-export status
            State:    Disable
            Running Status:    Not Running
            Platform support:    Supported
  4. Save your changes.

    hostname (config)# write memory