The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing devices

Prev Next

A device provides a usable instance of a plug-in and its commands. A playbook runs the commands to exchange data with upstream and downstream systems and services. For example, the VirusTotal - Indicator Enrichment playbook uses the Virustotal device to extract indicators from a threat and uses the VirusTotal service to enrich those indicators.

The Devices page (Response > Devices) provides details about each device, such as the plug-in it uses, its status, whether the device is configured, and the playbook that uses it.

HelixXDR_DevicesPage.png

There are two types of devices:

  • The Datastore device is used by every playbook. It writes playbook execution results to a data store so the results can be displayed as playbook activity in the Trellix Helix Web UI. Authentication for this device is handled implicitly so it requires no configuration.

  • The other devices are specific to the provided playbooks. A single device can be used by more than one playbook. For example, the Microsoft Azure - Disable Users and Microsoft Azure - Users Enrichment playbooks both use the Azure device. You must configure authentication credentials for these devices.

Important

Playbooks cannot be executed if the devices they use are not configured. Warnings are displayed on the Devices page for devices that are not configured.

Note

Devices are enabled by default.