The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Syslog fields directory

Prev Next

The syslog custom configuration can be edited in the <Database Security install dir>/conf/server-custom.properties file.

The following files need to be copied into this file from the <install dir>/webapps/ROOT/WEB-INF/config/application/server.properties file. You can view this file to see how CEF and Sentinel are configured.

Note

Do not change the server.properties file. All changes should be made in the server-custom.properties file.

Verify that all changes comply with the CEF protocol:

  • The header should have pipe (|) delimited fields

  • The body should have space delimited 'key=value' format.

    log.format.body.custom=externalId=$id$ rt=$executionTime.time$

    cs1=$database.name:20$ cs1Label=DBMS dst=$agent.ip$ src=$sourceIP$

    duser=$execUser:20$ suser=$osUser:20$ shost=$sourceHost:30$ dproc=$execProgram:20$

    act=$cmdType:15$ cs2=$operation:225$ cs2Label=SqlStatement

    cs3=$accessedObjects.name:200$ cs3Label=AccessedObjects

    log.format.header.custom

    =CEF:0|Trellix|Database Security|$serverVersion$|alert|$rules.name:150$|$importance$|

    log.format.header.escaping.custom=\\|

    log.format.header.seperator.custom=,

    log.format.body.escaping.custom=\=

    log.format.header.escape.char.custom=\\

    log.format.body.escape.char.custom=\\

    log.format.body.seperator.custom=|

    log.format.empty.value.custom=

    log.format.length.value.custom=255

    log.format.convert.newline.custom=true

You can then change log.format.body.custom to fit your format. The format is flexible. Each keyword identified by $<key word>$ is replaced with its value from the alert. It is also possible to specify a maximum length for the field.

For example: $agent.hostname:20$

If the length is not specified, the value of log.format.length.value.custom is used.

The following keywords can be used to define the format.

Keyword

Description

$clientInfo$

Client info field from Oracle database (string, maximum: 100)

$executionTimeMillis$

Execution time in millis format (number, 64-bit)

$executionTimeStr$

Execution time in date format: dd MMM yyyy HH:mm:ss (string, maximum: 32)

$severity$

Severity of the alert (High, Medium, Low) (string, maximum: 20)

$agent.hostname$

Host name of the sensor the alert was received from (string, maximum: 255)

$operation$

Statement executed (string, unlimited)

$osUser$

OS user (string, maximum: 100)

$execUser$

Database user (string, maximum: 100)

$realExecUser$

Real database user (string, maximum: 100)

$serial$

Oracle session serial (number, maximum: 64-bit)

$sid$

Session ID (number, maximum: 64-bit)

$terminal$

Terminal (string, maximum: 100)

$execProgram$

Executing program (string, maximum: 100)

$sourceHost$

Source host (string, maximum: 255)

$sourceIP$

Source IP address (string, maximum: 16)

$databaseName$

Database name (string, maximum: 255)

$accessedObjects.name$

Delimited list of accessed objects pipe; (string, unlimited)

$clientId$

Oracle client Identifier field (string, maximum: 64)

$cmdType$

SQL command type (string, maximum: 64)

$module$

Oracle module field (string, maximum: 64)

$contextInfo$

Microsoft SQL context info field; (string, maximum: 200)

$logonTime$

Session log on time (string, maximum: 32)

$inflowObjects.name$

Delimited list of inflow accessed objects pipe, delimited (string, unlimited)

$inflowSQL.statement$

Inflow SQL statement (string, unlimited)

$enduserName$

End-user name (relevant for IDentifier only) (string, maximum: 64)

$enduserModule$

End-user module (relevant for IDentifier only) (string, maximum: 64)

$enduserAction$

End-user action (relevant for IDentifier only) (string, maximum: 64)

$enduserIP$

End-user IP address (relevant for IDentifier only) (string, maximum: 16)

$action$

Oracle action field (string, maximum: 64)

$rules.name$

Rules that triggered the alert (string, unlimited)

$rules.ruleTags.name$

Tags used in the rules that triggered the alert (string, unlimited).

$rules.comment$

Rule comment field (string, unlimited)

$id$

Alert ID (number, 64-bit)

$database.type$

Type of database. Possible values ORACLE, MSSQL, MSSQL2000 (string, maximum: 32)

$database.version$

version of the database (string, maximum: 255)

$agent.ip$

IP address of the monitoring agent (string, maximum: 32)

The server must be restarted after modifying the server-custom.properties file before the changed properties can take effect.