The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Using the layer 7 metadata event exporter to send events to a Splunk Enterprise Server

Prev Next

The Layer 7 Metadata Event Exporter can send Layer 7 metadata generated from an appliance to the Splunk Enterprise server for further analysis.

For details about how to configure this feature, see Enabling or disabling the layer 7 metadata event exporter using the Web UI or Enabling or disabling the layer 7 metadata event exporter using the CLI on page 1.

Note

When Layer 7 Metadata Event Exporter is enabled, Evidence Collector must be enabled before Comm Broker is functional.

The interactions of the Layer 7 Metadata Event Exporter with the Evidence Collector and Comm Broker configurations are listed in the following table.

Configuration

Interaction

Default configuration.

Layer 7 Metadata Event Exporter is disabled.

Evidence Collector is enabled when the Layer 7 Metadata Event Exporter is enabled.

The nxlog process is restarted and both Evidence Collector and Layer 7 Metadata Event Exporter are functional.

Comm Broker is enabled when the Layer 7 Metadata Event Exporter is enabled.

Layer 7 Metadata Event Exporter is functional, but Comm Broker functionality stops because Evidence Collector is not functional.

Evidence Collector and Comm Broker are both enabled, and then the Layer 7 Metadata Event Exporter is enabled.

The nxlog process is restarted. Evidence Collector, Comm Broker, and Layer 7 Metadata Event Exporter are functional.

Evidence Collector and Comm Broker are both disabled, and then the Layer 7 Metadata Event Exporter is enabled.

The nxlog process is restarted and the Layer 7 Metadata Event Exporter is functional.