The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix FRP client events

Prev Next

Enforcement of Trellix FRP policies generates client events, which include the Event ID and appropriate information related to the event.

Removable media events

Event types

Event ID

Event

Definition

20500

Removable Media Device Insert Event

This event is reported whenever any type of removable media is inserted in the client.

Event severity: 0

20501

Removable Media User Response Event

This event is reported whenever the user clicks Yes or No in the Removable Media Format Message window.

Event severity: 0

20502

Removable Media Initialization Start Event

This event is reported whenever the user clicks Initialize or Cancel in the Removable Media Initialization window.

Event severity: 0

20503

Removable Media Initialization End Event

This event is reported when initialization is complete.

Event severity: 4

20504

Removable Media Device Ejection Event

This event is reported whenever any type of removable media is ejected from the client.

Event severity: 0

20509

Removable Media Device Upgrade Event

This event is reported whenever the removable media is being upgraded to support large file sizes (> 4GB).

Event severity: 0

20521

Removable Media Application Upgrade event

This event is reported when the removable media application is upgraded.

20559

Removable Media Authorization event is either successful or failure

This event is reported when the user's Removable Media Authorization is either successful or failure.

20560

Removable Media Recovery event is either successful or failure

This event is reported when the user's Removable Media Recovery is either successful or failure.

20561

Removable Media Authentication event is either successful or failure

This event is reported when the user's Removable Media Authentication Change is either successful or failure.



  • 20553 & 54 Event ID are replaced with 20559 (removable media authentication/authorization)

  • 20555 & 56 Event ID are replaced with 20560 (RM recovery)

  • 20557 & 58 Event ID are replaced with 20561 (RM authentication details change)

Event details

Information type

Definition

Event ID

Event ID number

System

  • User information (DomainName\UserName)

  • Time-stamp

Initialization

  • Initialization state (Failed, Canceled, Successful)

  • Backup state (None, Failed, Canceled, Successful)

  • Time taken for initialization in seconds

  • Time taken for backup in seconds

  • Backup size in GB

  • Size of protected part (only when initialization has completed successfully, in GB)

Device

  • Size (in GB)

  • File system of device (FAT32, NTFS, EERM)

    Note

    File system for devices with new container format (support for files > 4 GB) are shown as FAT32; devices with legacy container are shown as EERM.

  • Vendor name

  • Product name

  • Exempted (Yes, No, Unknown)

  • Protected (Yes, No, Unknown) USB and CD/DVD media encrypted by either onsite only access or offsite access are both considered protected devices. They appear in both Trellix FRP queries as protected media.

    Note

    Any new events sent from the Trellix FRP client to ePO - On-prem will have an updated media status.

Event specific fields

User response — Valid for events 20501 and 20502 only



Optical Media client events

Event types

Event ID

Event

Definition

20505

Optical Media Initialization Start Event

This event is reported whenever the user clicks Initialize or Cancel in the Initialization window.

Event severity: 0

20506

Optical Media Initialization End Event

This event is reported when initialization is complete.

Event severity: 0

20507

Optical Media Insertion Event

This event is reported whenever an optical media is inserted in the client.

Event severity: 0

20508

Optical Media Ejection Event

This event is reported whenever a optical media is ejected from the client.

Event severity: 0



Event details

Information type

Definition

Event ID

Event ID number

Computer

  • Name of the computer

  • User name

  • IP address

  • Operating system type

Media type

  • For Optical Media Initialization Start Events, the smallest disk type that can hold archived data (ISO, CD, DVD, or DVD-DL)

  • For Optical Media Initialization End Events, the physical media detected (for example, CD-ROM)

  • For Optical Media Insertion and Ejection Events, "Optical"

Device

  • Disk globally unique identifier (GUID)

  • Protected (Yes, No, Unknown) (only CD/DVDs protected by the "offsite access" options are considered protected)

  • Protected size (GB)

    • For Optical Media Initialization Start Events, the value is 0

    • For Optical Media Initialization End Events, the size of the encrypted archive

    • For Optical Media Insertion and Ejection Events, the size of the encrypted archive if the media is Trellix FRP encrypted

Event description

  • Description of the event

  • Event generation time

Event specific fields

Initialization state (Failed, Canceled, Successful). This is applicable for Optical Media Insertion and Ejection Events only.



Note

Only relevant information is captured in each event. For example, a device insert event does not contain the initialization state.

Trellix FRP: Key Authentication events

Event types

Event ID

Event

Definition

20510

Token initialization success event

This event is reported when token initialization is complete.

Event severity: 0

20511

Token initialization failure event

This event is reported when token initialization fails.

Event severity: 1

20512

Authentication success event

This event is reported when authentication successfully completes.

Event severity: 0

20513

Authentication failure event

This event is reported when authentication fails.

Event severity: 1

20514

Authentication token invalidation event

This event is reported when an authentication token has been invalidated by exceeding permitted incorrect attempts.

Event severity: 1

20515

Authentication change success event

This event is reported when an authentication change successfully completes.

Event severity: 0

20516

Authentication change failure event

This event is reported when an authentication change fails.

Event severity: 1

20517

Authentication recovery success event

This event is reported when authentication recovery successfully completes.

Event severity: 0

20518

Authentication recovery failure event

This event is reported when authentication recovery fails.

Event severity: 1

20519

Authentication recovery expired event

This event is reported when the authentication recovery password has expired based on Trellix FRP Key Authentication settings.

Event severity: 1

20520

Authentication lockout event

This event is reported when authentication locks out for the user.

20522

Advance Debug Option event

This event is reported when the device inserted by the user is exempted by the system for better security.



Cloud provider client events

Event types

Event ID

Event

Definition

20551

Cloud provider report event

This event is reported when the cloud provider sends a report to the ePO - On-prem server, even if any protection level is not selected.

20552

Cloud provider audit event

This event is reported when the cloud provider sends an audit-level report to the ePO - On-prem server, when the Audit protection level policy is selected.



Self-Protection events

To monitor or troubleshoot Self-Protection deployment on ePO clients, use FRP: Self-Protection Events query from ePO Queries & Reports.

Event types

Event ID

Event

Definition

20564

Self-Protection Enable Event

This event is reported when the Self-Protection enabling task is performed in the client.

20565

Self-Protection Disable Event

This event is reported when the Self-Protection disabling task is performed in the client.

20566

Self-Protection Install Event

This event is reported when the Self-Protection installation task is performed in the client.

20567

Self-Protection Uninstall Event

This event is reported when the Self-Protection uninstallation task is performed in the client.