The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Note about upgrading the Sensor from 10.1 or 11.1 to 11.1.5.44

Prev Next

If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.44, read the following sections carefully.

Integration with Trellix Investigation Analysis

Trellix Investigation Analysis (IA) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. IA provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.

Starting with this release of 11.1, Trellix IPS offers integration capability with IA appliances or IA cluster, and exports netflow records and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to IA as per the configuration and filter parameters set on the IA. The alert data, L7 metadata information, and flow records exported by Trellix IPS are displayed on the Dashboard of IA's Web UI which you can review and analyze further for the detection and analysis of network threats.

You need to perform the following steps to enable integration with Trellix IA:

  1. Create Client Profile using the IA Command Line Interface (CLI). During the configuration of the Client Profile, you can setup specific alert severity threshold and enable protocols for L7 metadata information which you want to be exported to IA, as per your requirement.

    Note

    Currently, IPS Sensors support the export of L7 metadata related to HTTP, HTTPS, SMTP, and FTP protocols only to IA.

  2. Create Client Group on the IA CLI which enables you to assign the required Client Profile to it. A hash token value of 32 bytes is also generated on the completion of Client Group configuration task on the IA CLI, which is used by Trellix IPS for authentication purpose.

    Note

    You can create up to 20 Client Profiles and 10 Client Groups on an IA appliance based on your requirement.

  3. Configure the required Client Groups created on the IA CLI, which includes adding details such as Client Group name, IP address of the associated IA appliance, and the authentication hash token, in the Manager.

  4. Enable the association of the Client Group configured in the Manager at the domain level or device level.

    Note

    You can configure multiple Client Groups in the Manager and enable their association per-domain or per-Sensor basis.

The following tabs are available for enabling IA integration in the Manager:

Navigation path

Description

At Global-level

Devices → <Admin Domain Name> → Global → IPS Device Settings → IA Integration → Client Group Configuration

To configure the Client Group details in the Manager

Devices → <Admin Domain Name> → Global → IPS Device Settings → IA Integration → Client Group Association

To enable association of any Client Group for the admin domain as well as child domains

Note

If you enable the IA integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain.

At Device-level

Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → IA Integration → Client Group Association

To enable association of any Client Group per Sensor basis within any domain

Note

You must configure the Client Group details in the Manager to enable its association at the domain or device level. You can configure any Client Group by using the Client Group Configuration tab available at the Global-level, or on the Client Group Association tabs available at both domain and device levels.

Following is the list of Sensor CLI commands that have been added in support of Trellix IA integration:

Debug Mode

Command

Description

show ia status

This command displays IA feature status and communication status between Trellix IPS and Trellix IA, along with other configuration details related to IA integration.

getiastats

This command displays counter specifics related to IA config and metadata export.

cleariastats

This command clears all the IA config and metadata statistics-related counters in the Sensor.

ianetflowstat

This command displays internal statistics specifics related to netflow and L7 metadata from datapath side.



Sensor CLI commands

Along with commands related to Trellix IA integration documented above, the following Sensor CLI command is updated:

Debug Mode

Command

Description

rspstat

Displays the datapath attack response related statistics. With this release, it also displays the number of attacks superseded by alert-correlation.