The Integration Summary report provides a summary of configurations done in the Manager to integrate with other products such as, ePO - On-prem and Trellix Global Threat Intelligence Configuration.
To generate the report, do the following:
Click the Manager tab from the Manager Home page.
Select <Admin Domain Name> → Reporting → Configuration Reports → Integration Summary.
Select the Report Format.
Click Run.
The Integration Summary Report displays the following details:
ePO DB Configuration
Telemetry Submission
Technical Contact Information
Trellix Global Threat Intelligence
ePO DB Configuration
The integration between the Manager and the ePO server is done with the help of an extension file. After the installation of the extension file, the detail is listed in this report and its fields are described in the following table:
Field Name | Description |
|---|---|
Admin Domain | The selected admin domain for the summary report to be generated. |
Endpoint Summary Queries | Displays details of the Endpoint Summary Queries which can be enabled or disabled. |
Endpoint Lookup | Displays details of the Endpoint Queries which can be enabled or disabled. |
Endpoint Tagging | |
Server Name or IP Address | The name or the IP of the ePO server running the extension file. Note that this ePO server should have the details of the hosts covered by the admin domain. Contact your ePO administrator for the server name and IP. |
Server Port | Specify the HTTPS listening port on the ePO server that will be used for the Manager-ePO communication. Contact your ePO administrator for the port number. |
User Name | The username to be used while connecting to the ePO server. Trellix recommends you use a local ePO user account with View-only permissions. |
For more information on ePO, refer to ePO documentation.
Note
If you update the IP address of ePO from the Manager in the Manager → <Admin Domain Name> → Integration → ePO Integration page, you should reboot the Manager.
Telemetry Submission
The details of what has actually been sent to Trellix are described in the following table:
Field Name | Description |
|---|---|
Alert Data Details | This field shows the details of the Alert data sent to Trellix for each attack. |
Only send data for following alert severities (Filter) | This field helps to configure the levels of severities. |
Alert Data Summary | This field shows the alert summary information sent hourly to Trellix like List of Trellix IPS attack IDs seen. |
General Setup | This field shows the general setup information sent daily to Trellix like Manager software version and active signature set version. |
Feature Usage | This field shows the feature information sent daily to Trellix like the number of default policies in use. |
Technical Contact Information
The details of your contact information that are provided to Trellix ARC are described in the following table:
Field Name | Description |
|---|---|
Send Technical contact information | Technical contact information is gathered to communicate End of Life and other key milestones. |
First Name | The first name of the contact person. |
Last Name | The last name of the contact person. |
Street Address | The street address of the contact person. |
Phone Number | The phone number of the contact person. |
E-mail Address | The email address of the contact person. |
Global Threat Intelligence
The details of private TI cloud integration are described in the following table:
Field Name | Description |
|---|---|
Private GTI Cloud Integration | Displays if the private GTI cloud integration is enabled or disabled. |
Private GTI Cloud Server IP | Displays the server IP of the private GTI cloud. |