Hello,
We're investigating an issue with a Trellix HX Audit integration in Google SecOps and would appreciate any guidance from others who have worked with this feed.
Environment
- Google SecOps SIEM
- Trellix HX / FireEye HX API Feed
- Log Type:
TRELLIX_HX_AUDIT
Issue
The feed was ingesting normally for an extended period and then abruptly stopped receiving audit events.
Observed ingestion pattern:
Normal ingestion for several weeks
Sharp reduction in volume
Subsequently dropped to 0 events/day
Current Status
- Feed status shows OK/Healthy
- Feed is enabled
- Feed was recreated with the same configuration
- Other Trellix HX-related feeds continue to ingest successfully
- No parsing errors
- No validation errors
- No indexing errors
Specific Event Type Affected
The primary missing events are Bulk Acquisition audit events, such as:
Bulk Acquisition Initiated
Bulk Acquisition Completed
These events were previously being ingested into Google SecOps under TRELLIX_HX_AUDIT.
Additional Findings
While reviewing historical HX audit logs, we confirmed that Bulk Acquisition activities were previously audited through HX API operations related to bulk acquisition workflows.
We're trying to understand:
- Whether Bulk Acquisition audit events require any special HX configuration or permissions.
- Whether the HX Audit API can stop exposing these events while the feed itself remains healthy.
- How others have validated that Bulk Acquisition audit records are still being returned by the HX Audit API.
- Whether there are any known issues affecting
TRELLIX_HX_AUDITingestion for Bulk Acquisition activities
All the permission have been granted properly as to the API account
Does it have a mandiant dependency as this issue took place after removing mandiant defense from the environment.
But the secops configuration document does not suggest or say about mandiant dependency
Also MD_Advance licence is in place for Trellix HX that supports bulk acqusision
Is there anything on the server level that needs done from trellix side for Fe_services
Any suggestions on additional HX-side checks or API validation steps would be greatly appreciated.

