Trellix

Trellix

Security Operations: Trellix (formerly McAfee) SIEM (Security Information and Event Management) Technical Information

Trellix (former McAfee) SIEM configuration example

  • McAfee SIEM configuration example
    • Enterprise Security Manager (ESM)

A core component of McAfee SIEM that stores events in a dedicated database and provides views, alarms, report output, rule management, consoles, etc.

    • Event Receiver (ERC)

Receives device/OS/application events and forwards them to ESM

    • Advanced Correlation Engine (ACE)

Dedicated component to handle correlation analysis

Inquiry/Document request

In charge of Macnica Trellix Co., Ltd.

  • TEL:045-476-2010

Mon-Fri 8:45-17:30