When you add the domains in Trellix Logon Collector, it contacts the AD server and collects the details, such as the IP address, user name, host name, and so on of the currently logged on users.
When you integrate Trellix Logon Collector and the Manager, Trellix Logon Collector sends all the user details that it currently has to the Manager. The information sent includes the following:
IP to user mapping
List of users and the user groups to which they belong
List of user groups
Note
Communication between the Manager and Trellix Logon Collector occurs over SSL.
Trellix Logon Collector updates the Manager continuously. So, at any point in time, the current user-related data with Trellix Logon Collector is there with the Manager as well.
Consider situations such as the following:
A user logs off from a host and a user logs on from that host again
You add a user to more user groups
You delete a user group in the AD
For all such cases, as soon as Trellix Logon Collector has the updated information, it is reflected in the Manager as well.
Tip
When you add new users in the AD, modify user groups, or delete user groups you must run the TLC Refresh Users server task manually in Trellix Logon Collector. Then the current data from the AD is available in the Manager.
If you have configured MDR, then the process explained above happens independently for both the Managers. The Managers themselves do not exchange any user details.
For the following cases, the information might not immediately reflect in the Manager:
If a user logs off from a host and no user is currently logged on
You remove a user from a user group
You delete a user group. In this case, the user attributes are updated but the deleted user group is visible in the Manager