Trellix Web Gateway Security Operations
Unified capability for security operations teams to monitor, investigate, and respond to web security threats using Trellix Web Gateway. Combines traffic log analysis, security event investigation, threat statistics, and appliance health monitoring for SOC analysts and network security engineers.
What You Can Do
MCP Tools
get-security-events
Retrieve security events from Web Gateway including malware detections and policy violations. Use for incident investigation and threat hunting.
get-traffic-logs
Retrieve web traffic logs for forensic analysis, compliance auditing, and user behavior investigation.
get-threat-statistics
Get threat statistics to understand attack patterns, malware trends, and security posture over time.
get-traffic-statistics
Get web traffic statistics for capacity planning and anomaly detection.
get-top-urls
Get top accessed URLs to identify potential policy violations or unusual browsing patterns.
get-top-categories
Get top URL categories to understand web browsing patterns and policy effectiveness.
get-system-logs
Retrieve Web Gateway system and audit logs for compliance and change tracking.
list-appliances
List Web Gateway appliances and check their operational health status.