Trellix ETP collector
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( |
|
Running environments |
|
Populated Devo events |
|
Flattening preprocessing |
|
Data sources
Data source | Description | API endpoint | Collector service name | Devo table | Available from release |
Alert Summary | Gets a list of advanced threat alerts in summary format. |
|
|
|
|
Email Trace | This retrieves email trace information as per the attributes |
|
|
|
|
User Activity | Searches the user activity for the Admin Users of the client |
|
|
|
|
Statistics | Users can view the statistics of emails on the ETP Portal. |
|
|
|
|
For more information on how the events are parsed, visit our page.
Flattening preprocessing
Data source | Collector service | Optional | Flattening details |
---|---|---|---|
Alert Summary |
|
| Flattening not required. |
Email Trace |
|
| Flattening not required. |
User Activity |
|
| Flattening not required. |
Statistics |
|
| Flattening not required. |
Minimum configuration required for basic pulling
Although this collector supports advanced configuration, the fields required to retrieve data with basic configuration are defined below.
This minimum configuration refers exclusively to those specific parameters of this integration. There are more required parameters related to the generic behavior of the collector. Check setting sections for details.
Setting | Details |
---|---|
| The Trellix ETP API api key used for authorization. |
| Get the ETP instance ID you want to fetch the alerts data for. |
See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.
Accepted authentication methods
Authentication method | API Key | Instance ID |
---|---|---|
Access Token | API Key | REQUIRED | REQUIRED |
Run the collector
Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (Cloud collector), or deploy and host the collector in your own machine using a Docker image (On-premise collector).
Collector services detail
This section is intended to explain how to proceed with specific actions for services.
Alert Summary
Email Trace
User Activity
Statistics
Collector operations
This section is intended to explain how to proceed with specific operations of this collector.
Change log
Release | Released on | Release type | Details | Recommendations |
---|---|---|---|---|
| Jan 8, 2024 | Changed |
| |
| Nov 13, 2023 | NEW FEATURE | Released the first version of the Trellix ETP collector. |
|