OS changes are automatically included in alerts when Trellix Helix mode is enabled on an appliance.
To include OS changes:
Go to CLI configuration mode:
hostname > enable hostname # configure terminal
Enable the inclusion of OS changes:
hostname (config) # datastreaming helix alert-metadata include-oschanges
Verify your change:
hostname (config) # show datastreaming helix
To exclude OS changes
Use the
no datastreaming helix alert-metadata include-oschangescommand.