The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the Evidence Collector Module details using the CLI

Prev Next

Use the show tapsender health command to monitor the following health states of the Evidence Collector module:

  • Not Authenticated—The Evidence Collector is in the process of authenticating with Helix.

  • Authenticated—The Evidence Collector has been authenticated with Helix and is in the process of connecting to the VPC within an AWS endpoint.

  • Connected—The Evidence Collector is connected to the VPC within an AWS endpoint and is sending the network event logs.

  • Authentication Failure—The Evidence Collector failed to authenticate with Helix because either communication failed or the client certificate expired.

  • Failure—The Evidence Collector failed to connect to the VPC within an AWS endpoint.

Use the show tapsender stats command to view the statistics about the frequency of event logs that are generated by the Network Security appliance and sent to Helix. The network event logs report the number of events per second (EPS). EPS is part of event logging that is used to monitor and record every instance of events that is generated by the Network Security appliance.

For details about these commands, see the CLI Command Reference.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Configure a valid hostname for the VPC within an AWS endpoint.

  • Enable the Evidence Collector module.

To view the health details of the Evidence Collector module:
  1. Go to CLI enable mode.

    hostname > enable
  2. View the health status of the Evidence Collector module.

    hostname # show tapsender health
    • If the Evidence Collector is in the process of authenticating with Helix, the following state appears:

      Not Authenticated

    • If the Evidence Collector has been authenticated with Helix and is in the process of connecting to the VPC within an AWS endpoint, the following state appears:

      Authenticated

    • If the Evidence Collector is connected to the VPC within an AWS endpoint and is sending the network event logs, the following state appears:

      Connected

    • If the Evidence Collector failed to authenticate itself with Helix because either communication failed or the client certificate expired, the following state appears:

      Authentication Failure

    • If the Evidence Collector failed to connect to the VPC within an AWS endpoint, the following state appears:

      Failure

To view the event statistics for the Evidence Collector module:
  1. Go to CLI enable mode.

    hostname > enable
  2. View the event statistics about the frequency of event logs that are generated by the Network Security appliance.

    hostname # show tapsender stats
    INPUT STATS
    -----------
    
    Total L7-Meta-data Events Received                    : 0
    L7-Meta-data Average EPS Rate                         : 0
    
    OUTPUT STATS
    ------------
    Total Json and L7-Meta-data Events sent               : 0