This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!

Step 1: Enable console access

This procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the Trellix HX console.

  1. Navigate to Admin > Appliance Settings.

    Screen Shot 2021-03-05 at 12.11.52 PM.png
  2. Click User Accounts on the left.

    Screen Shot 2021-03-05 at 12.12.19 PM.png
    • For Username add Expel.

    • Ensure the Role is set to Admin.

    • Type a Password.

Step 2: Generate API credentials

This procedure creates an authentication token that allows the Expel Assembler to access the Trellix HX API.

  1. Go to the User Accounts section.

  2. For Username add expelapi.

    Screen Shot 2021-03-05 at 12.12.47 PM.png
  3. Make sure the Role is set to API Admin.

  4. Type a Password.

Step 3: Configure the technology in Workbench

  1. In a new browser tab, log into https://workbench.expel.io.

  2. On the console page, navigate to Settings and click Security Devices.

  3. At the top of the page, click Add Security Device.

  4. Search for and select Trellix HX.

    Screen Shot 2021-03-05 at 12.13.38 PM.png
  5. Select an Assembler from the list with network connectivity to the Trellix HX device. Select the assembler you set up in Getting connected to Expel Workbench.

    Screen Shot 2021-03-05 at 12.14.06 PM.png
    • For Name type the host name of the Trellix HX device.

    • For Location type the geographic location of the appliance.

    • For Server address type the Trellix HX device IP and communications port in the following format: https://<serverip>:3000. Find the Device IP in the Trellix HX console > Admin > Appliance Settings > Network.

    • For API Password and API Username type the API Admin credentials previously created in the Trellix HX console in Step 2.

    • In the optional Console Login section, for Username and Password, type the Admin credentials created in the Trellix HX console in Step 1.

Related terms

FireEye, FireEye HX, Fire Eye