The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Splunk Enterprise integration

Prev Next

When you enable integration between a Splunk Enterprise server and a Network Security appliance, the Layer 7 Metadata Event Exporter on the Network Security appliance sends Layer 7 metadata events to the Splunk Enterprise server for further searchablity, indexing and analysis of your network data. The Layer 7 Metadata Event Exporter is used to collect and aggregate logs generated by the Network Security appliance and sends them over TCP, UDP or HTTPS to your configured Splunk Enterprise server.

With Splunk Enterprise integration, you configure the Evidence Collector module to aggregate logs. The Comm Broker is not supported, but events will continue to be sent and received through the Evidence Collector module.

Note

You cannot integrate a SmartVision mode sensor with a Splunk Enterprise server. SmartVision mode sensors do not support the Layer 7 Metadata Event Exporter feature.

To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance, see Configuring the VPC within an AWS endpoint using the CLI.

You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.

Supported Trellix Network Security appliances

Splunk integration is supported on the following hardware and virtual appliances

  • NX 6500, NX 5500, NX 4500, NX 3500, NX 2550, NX 2500, NX 1500

  • NX 1500V, NX 2500V, NX 4500V, NX 6500V

Supported software versions

  • Splunk 6.4.2 or later for HTTPS event collector

  • TLS 1.2

Task list for managing Splunk Enterprise integration

Complete the steps for managing Splunk Enterprise integration in the following order:

  1. Gather all the information that you will need to begin exporting Layer 7 metadata events to your Splunk Enterprise server.

  2. Understand Splunk interaction with Evidence Collector and Comm Broker. See Using the layer 7 metadata event exporter to send events to a Splunk Enterprise server.

  3. Create the HTTP Event Collector token on the Splunk Enterprise server. See Creating an HTTP event collector token on a Splunk Enterprise Server

  4. Enable HTTP Event Collector. See Enabling an HTTP Event Collector token service on a Splunk Enterprise Server.

  5. Enable the Layer 7 Metadata Event Exporter. See Enabling or Disabling the Layer 7 Metadata event exporter using the Web UI or Enabling or Disabling the layer 7 metadata event exporter using the CLI .

  6. View details about the health and event statistics for the Layer 7 Metadata Event Exporter. See Viewing the layer 7 metadata event exporter details using the CLI.