Loading

Trellix ePO Cloud

Version 1.16.0 (View all)
Subscription level
What's this?
Basic
Developed by
What's this?
Elastic
Ingestion method(s) API
Minimum Kibana version(s) 9.0.5
8.19.2

The Trellix ePO Cloud integration allows users to monitor devices, events and groups. Trellix ePolicy Orchestrator is centralized security management platform to orchestrate and manage all your endpoints.

Use the Trellix ePO integration to collect and parse data from ePO Cloud. This integration does not support on-premises installations of ePO. Then visualize that data from Trellix to identify threats through search, correlation and visualisation within Elastic Security.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ. Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

The Trellix ePO Cloud integration collects three types of data: devices, events and groups.

Devices fetch all devices.

Events fetch all events.

Groups fetch all groups.

Reference for Rest APIs of Trellix ePO Cloud.

Elastic Agent must be installed. For more information, refer to the link here.
The minimum kibana.version required is 8.7.1.
This module has been tested against the Trellix ePO Cloud API Version v2.

  1. Go to the Trellix Developer Portal and Login by entering an email address and password.

  2. Go to Self Service → API Access Management.

  3. Enter Client Type.

  4. Select IAM Scopes as below:

    APIs Method Types
    Devices GET
    Events GET
    Groups GET
  5. Click Request.

  6. Copy Client ID, Client Secret and API Key.

  7. Go to kibana and select integration -> Trellix ePO Cloud.

  8. Click Add Trellix ePO Cloud.

  9. Provide Client ID, Client Secret and API Key that we've copied from Trellix.

Note:

  • The data retention period for events available via this API is 3 days.

This is the Device dataset.

This is the Event dataset.

This is the Group dataset.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.