InfoCollector is an information collection tool, bundled with Manager that allows you to easily provide Trellix with Trellix IPS-related log information. Trellix can use this information to investigate and diagnose issues you may be experiencing with the Manager.
InfoCollector can collect information from the following sources within Trellix IPS:
Information Type | Description |
|---|---|
Ems.log Files | Configurable logs containing information from various components of the Manager. The current ems.log file is renamed when its size reaches 3MB, using the current timestamp. Another ems.log is created to collect the latest log information. |
Configuration backup | A collection of database information containing all Trellix IPS configuration information |
Configuration files | XML and property files within the Trellix IPS config directory |
Fault log | A table in the Trellix IPS database that contains generated fault log messages |
Sensor Trace | A file containing various Sensor-related log files |
Compiled Signature | A file containing signature information and policy configuration for a given Sensor |
InfoCollector is a tool that can be used both by you and by Trellix.
Trellix systems engineers can use the InfoCollector tool to provide you with a definition (.def) file via email. This file is configured by Trellix to automatically choose information that Trellix needs from your installation of Trellix IPS. You simply open the definition file within the InfoCollector and it will automatically select the information that Trellix needs from your installation of the Manager.
Alternatively, a manual approach can also be used with InfoCollector, and you can select information yourself to provide to Trellix. For example, Trellix may ask you to select checkboxes that correspond to different sets of information available within Trellix IPS.