The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Helix integration

Prev Next

When you enable integration between Helix and the Network Security appliance, the Evidence Collector module on the Network Security appliance sends the network event logs to Helix for further analysis. The Evidence Collector module is a log aggregator that collects logs generated by the Network Security appliance. You also can configure your own custom filter rules or reset the rules to the default rules that Trellix provides to filter out each event type (HTTP, SMTP, DNS, TLS, and so forth) based on the JSON value and the corresponding event field on the Network Security appliance. The events that match the filter criteria would be dropped. For details about the supported event types and how to add or delete the event filter rules, see Configuring event filter rules.

In Helix, the network event logs are correlated against the -specific alerts to perform further forensic analysis. Helix uses the information that is collected in the logs to identify malware or advanced persistent threat (APT) activity, identify known bad certificates, track malicious activity, and so on. The network event logs allow you to identify activity in your network before the -specific alert is triggered on the appliance. For details about collecting network event logs for Helix, see the Data Source Configuration Guide.

Note

Helix integration is not supported on the Web MPS x3xx appliances and the Network Security 10000 appliance.

Task list for managing Helix integration

Complete the steps for managing Helix integration in the following order:

  1. Gather all the information that you will need to begin forwarding events to your Helix Enterprise instance.

  2. Log in to the CLI to specify the settings for the Helix integration.

  3. Configure a valid hostname for the Helix Enterprise Virtual Private Cloud (VPC) within an Amazon Web Service (AWS) endpoint. For details about how to configure VPC within an AWS Endpoint, see Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint using the CLI.

  4. (Optional) Configure the Evidence Collector to use an HTTP proxy server. For details on how to configure the proxy server, see Configuring an HTTP proxy server using the CLI.

  5. If Helix Enterprise mode is not enabled on the appliance, import and apply the Helix Enterprise certificate and bootstrap files. See Importing a certificate and a private key for the Evidence Collector module.

  6. Enable the Evidence Collector module. For details about enabling the Evidence Collector module, see Enabling or disabling the Evidence Collector module using the Web UI or Enabling or disabling the Evidence Collector module using the CLI.

  7. View the details about the health states and event statistics for the Evidence Collector module. For details about how to view the health states and event statistics, see Viewing the Evidence Collector module details using the CLI.

  8. Configure the Communications Broker Sender (Comm Broker) to send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis. For details about how to configure the Comm Broker using the CLI and Web UI, see Configuring the Communications Broker Sender to send third-party logs to TAP.

  9. Configure event filter rules. For details about how to add and delete event filter rules, view event filter statistics, and reset event filters, see Configuring event filter rules.