The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the layer 7 metadata Event Exporter using the Web UI

Prev Next

In the Settings > External SIEM Integration area in the Evidence Collector page of a Network Security appliance, you can enable or disable the Layer 7 Metadata Event Exporter to collect logs generated by the Trellix appliance.

NX_L7ExporterSettings_scap.png

You specify the following Layer 7 Metadata Event Exporter settings.

Field

Description

Protocol

The protocol type (HTTPS, TCP or UDP) that is used to send the Layer 7 metadata events to the Splunk Enterprise server.

Host

The destination IPv4/IPv6 address of the Splunk Enterprise server.

Port

The port that the appliance uses to initiate a connection with the Splunk Enterprise server. Valid values are integers ranging from 514 to 65535.

Authorization Header

The authorization header that is used to create the HTTPS event collector token. The HTTPS Event Collector (HEC) token is the Splunk authorization header.

To enable the Layer 7 Metadata Event Exporter:
  1. In the Web UI, choose Settings > Evidence Collector.

  2. Click External SIEM Integration.

  3. In the Protocol drop-down list, choose HTTPS (Splunk Integration), TCP, or UDP.

  4. In the Host field, enter the destination IPv4/IPv6 address of the Splunk Enterprise server.

  5. In the Port field, enter the port that the appliance uses to initiate a connection.

  6. In the Authorization Token field, enter the authorization header that is used to create the HTTPS event collector token.

  7. Click Update.

  8. In the Enable Settings area, click the L7 metadata toggle button to enable the Layer 7 Metadata Event Exporter.

    The toggle button displays "ON" to show that the Layer 7 Metadata Event Exporter can collect logs generated by the Trellix appliance.

    NX_L7ExporterEnable_scap.png

    The following message appears:

    NX_TAPSenderConfigSuccess_scap.png
To disable the Layer 7 Metadata Event Exporter:
  1. In the Web UI, choose Settings > Evidence Collector.

  2. Click External SIEM Integration.

  3. In the Enable Settings area, click the L7 metadata toggle button to disable the Layer 7 Metadata Event Exporter.

    The toggle button displays "OFF" to show that the Layer 7 Metadata Event Exporter cannot collect logs generated by the Trellix appliance.

    NX_L7ExporterDisable_scap.png

    The following message appears:

    NX_TAPSenderConfigSuccess_scap.png