This quick start guide will help Accenture MDR customers configure to Trellix ePO SaaS allow logs to the Log Collection Platform (LCP).
The document includes the following topics:
Supported Versions
A list of supported versions is available in the Accenture MDR Supported Products List document (Accenture_MDR_Supported_Products_List.xlsx) which can be found in Accenture MDR Portal.
Port Requirements
Table 1-1: Port requirements for LCP communication.
Source | Destination | Port | Description |
LCP | Trellix ePO | 443 (TCP) | Default port |
Configuring of Trellix EDR
Type the first name, last name, and the email address of the user you wish to invite to create an account.
Click Invite.
An automated invite is sent to the user. They must set their credentials and activate their account to use Trellix ePO - SaaS. After the user account is activated, you can view their details in the Users pane.
Assign role to user created above in Trellix ePO - SaaS
Navigate to Trellix ePO ->SaaS, select Menu -> Configuration -> Users & Roles.
From the Users list, select a user to display the user details in the right pane.
The details show which roles are assigned to the selected user.
From the Unassigned Roles list, select the Trellix EDR Search API Access role .
Click Save Changes.
Below are the details required for pulling the logs :
Parameters | Value |
---|---|
URL | Below are the URL for different regions. Use the appropriate one. US : https://arevents.manage.trellix.com Singapore : https://areventssgp.manage.trellix.com Frankfurt : https://areventsfrk.manage.trellix.com Sydney : https://areventssyd.manage.trellix.com India : https://areventsind.manage.trellix.com Reference Link : Product Documentation | Trellix |
Client ID | 0oawz1wagXnxG7lUr2p6 NOTE : Client ID is a string provided by the vendor. It may or may not change in the future. For now, fixed string is provided here. |
User Name | Use the value that was created in the above steps |
Client Secret | Use the password that was created in the above steps |
LCP Configuration Parameters
Table 1-2: The Trellix ePO (API - 5060) properties to be configured by MDR are shown in the table.
Property | Default Value | Description |
URL | Custom Value | Below are the URL for different regions. Use the appropriate one. US : https://arevents.manage.trellix.com Singapore : https://areventssgp.manage.trellix.com Frankfurt : https://areventsfrk.manage.trellix.com Sydney : https://areventssyd.manage.trellix.com India : https://areventsind.manage.trellix.com Reference Link : Product Documentation | Trellix |
Client ID | Custom Value | Copy the Client ID from the above device configuration. |
User Name | Custom Value | Copy the User Name from the above device configuration. |
Client Secret | Custom Value | Copy the Client Secret Value from the above device configuration. |