If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.44, read the following sections carefully.
Integration with Trellix Investigation Analysis
Trellix Investigation Analysis (IA) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. IA provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.
Starting with this release of 11.1, Trellix IPS offers integration capability with IA appliances or IA cluster, and exports netflow records and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to IA as per the configuration and filter parameters set on the IA. The alert data, L7 metadata information, and flow records exported by Trellix IPS are displayed on the Dashboard of IA's Web UI which you can review and analyze further for the detection and analysis of network threats.
You need to perform the following steps to enable integration with Trellix IA:
Create Client Profile using the IA Command Line Interface (CLI). During the configuration of the Client Profile, you can setup specific alert severity threshold and enable protocols for L7 metadata information which you want to be exported to IA, as per your requirement.
Note
Currently, IPS Sensors support the export of L7 metadata related to HTTP, HTTPS, SMTP, and FTP protocols only to IA.
Create Client Group on the IA CLI which enables you to assign the required Client Profile to it. A hash token value of 32 bytes is also generated on the completion of Client Group configuration task on the IA CLI, which is used by Trellix IPS for authentication purpose.
Note
You can create up to 20 Client Profiles and 10 Client Groups on an IA appliance based on your requirement.
Configure the required Client Groups created on the IA CLI, which includes adding details such as Client Group name, IP address of the associated IA appliance, and the authentication hash token, in the Manager.
Enable the association of the Client Group configured in the Manager at the domain level or device level.
Note
You can configure multiple Client Groups in the Manager and enable their association per-domain or per-Sensor basis.
The following tabs are available for enabling IA integration in the Manager:
Navigation path | Description | |
|---|---|---|
At Global-level | → → → → → | To configure the Client Group details in the Manager |
→ → → → → | To enable association of any Client Group for the admin domain as well as child domains NoteIf you enable the IA integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain. | |
At Device-level | → → → → → → | To enable association of any Client Group per Sensor basis within any domain |
Note
You must configure the Client Group details in the Manager to enable its association at the domain or device level. You can configure any Client Group by using the Client Group Configuration tab available at the Global-level, or on the Client Group Association tabs available at both domain and device levels.
Following is the list of Sensor CLI commands that have been added in support of Trellix IA integration:
Command | Description |
|---|---|
| This command displays IA feature status and communication status between Trellix IPS and Trellix IA, along with other configuration details related to IA integration. |
| This command displays counter specifics related to IA config and metadata export. |
| This command clears all the IA config and metadata statistics-related counters in the Sensor. |
| This command displays internal statistics specifics related to netflow and L7 metadata from datapath side. |
Sensor CLI commands
Along with commands related to Trellix IA integration documented above, the following Sensor CLI command is updated:
Command | Description |
|---|---|
| Displays the datapath attack response related statistics. With this release, it also displays the number of attacks superseded by alert-correlation. |