The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integrating with Security Information and Event Management (SIEM)

Prev Next

NDR solutions offers alert notification capabilities to centralize threat monitoring and log analysis for security teams. It integrates seamlessly with Security Information and Event Management (SIEM) solutions such as Helix, Splunk, and Chronicle, and generic Syslog servers. Analysts can benefit from this data ingestion by centrally monitoring all threats and logs from assets across their network.

NDR supports sending alerts using either HTTP or RSYSLOG methods. It offers a wide array of formats to accommodate diverse SIEM requirements, including Common Event Format (CEF), Comma Separated Values (CSV), JavaScript Object Notation (JSON), Log Event Extended Format (LEEF), syslog formatted messages (SYSLOG), and Extensible Markup Language (XML). This allows users have granular control over alert notifications, enabling them to specify the alert severity level and the frequency at which notifications are sent.

You can integrate the SIEM solutions with your NDR appliance through CLI and Web UI.