Skip to content

Trellix (McAfee) ENS Integration

Overview

Trellix Endpoint Security (formerly McAfee ENS) provides threat prevention, firewall, and web control for endpoints. KYRA MDR collects Trellix events via the ePO syslog integration for centralized security monitoring. Supports Trellix ENS 10.7+ and ePO 5.10+.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Trellix ePolicy Orchestrator (ePO) server access
  • Registered Server configuration permissions in ePO
  • Network connectivity from ePO to the collector on port 514

Configuration

Configure syslog forwarding in Trellix ePO:

  1. Log in to the ePO Console
  2. Navigate to Configuration > Registered Servers
  3. Click New Server and select Syslog Server
  4. Configure:
Server Name: KYRA-MDR
Server Type: Syslog
Host: <collector-ip>
Port: 514
Protocol: TCP
Format: Common Event Format (CEF)
  1. Navigate to Automation > Automatic Responses
  2. Create a response rule that sends events to the KYRA-MDR syslog server
  3. Select event types: Threat Events, Compliance Events, and System Events

Collected Log Types

Log TypeDescriptionSecurity Use
Threat PreventionMalware detections and blocksEndpoint malware defense
FirewallEndpoint firewall eventsHost-based network control
Web ControlURL access and block eventsWeb security enforcement
Adaptive ThreatATP behavioral detectionsAdvanced threat defense
Access ProtectionFile and registry protectionHost integrity monitoring
DLPData loss prevention eventsSensitive data protection

Troubleshooting

No events in syslog: Verify the Automatic Response rule is enabled and configured to send events to the registered syslog server.

CEF formatting issues: Ensure the syslog format is set to CEF in the registered server configuration.

High volume: Use event filters in the Automatic Response rule to send only security-relevant events.

Contact kyra@seekerslab.com for support.