Trellix Enterprise Security Manager (formerly McAfee ESM)
Last updated
The IP address or hostname of your Trellix ESM (formerly McAfee ESM) appliance. Trellix ESM is an on-premises product; the base URL is unique to each deployment.
The port the ESM REST API is served on (optional, default: 443).
Choose this if your connection is going to be over HTTPS (optional, default: True).
The username of an ESM console account used to authenticate against the REST API.
The password of the ESM console account.
The amount of time (in seconds) to wait for API responses. (default: 30)
Default Values
Port: 443
Is Secure: True
Timeout: 30
Permissions Required
The account needs standard ESM REST API access. To list log-source data sources (devices) the user should be able to view the receiver and data source lists; admin rights ensure the full, unfiltered list is returned. To collect ESM console users, the account needs user-management read access. Please perform a connection test before running discovery to confirm the credentials and permissions are valid.
Last updated