The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create UCAPL alarms

Prev Next

Create alarms that meet Unified Capabilities Approved Products List (UCAPL) requirements.

  1. Create an Internal Event Match alarm matching on Signature ID for specific triggers:

    • When multiple failed logons for the same user reach an adjustable threshold, set the value to 306-36.

    • When a user account is locked due to reaching the no activity threshold, set the value to 306-35.

    • If a user tries to log on to the system after reaching the number of allowed concurrent sessions, set the value to 306-37.

    • When a system file integrity check fails, set the value to 306-50085.

    • When common access card (CAC) or web server certificates are about to expire set the value to 306-50081, 306-50082, 306-50083, or 306-50084.

      Note

      The alarm triggers 60 days before the certificate expires, then on a weekly basis. You cannot change the number of days.

  2. Configure an SNMP trap so that the alarm sends a trap to the NMS when it detects that the system is no longer operating in an approved or secure state.

    1. Create an alarm matching on any condition, then click Actions tab → Send Message.

    2. Click Add Recipients → SNMP, select the recipient, then click OK.

    3. Click Send Message → Configure → Templates → Add.

    4. Select SNMP Template for Type field and enter the text for the message, then click OK.

    5. On the Template Management page, select the new template and click OK.

    6. Complete the remaining alarm settings.

  3. Configure a syslog message so that the alarm sends a syslog message to NMS when it detects that the system is no longer operating in an approved or secure state.

    1. Create an alarm matching on any condition, then click Actions tab → Send Message.

    2. Click Add Recipients → Syslog, select the recipient and click OK.

    3. In the Send Message field, click Configure → Templates → Add.

    4. Select Syslog Template for Type field and enter the text for the message, then click OK.

    5. On the Template Management page, select the new template, then click OK.

    6. Complete the remaining alarm settings.

  4. Configure an SNMP trap so that the alarm notifies the appropriate Network Operations Center (NOC) in 30 seconds if a security log fails to record required events.

    1. Select System Properties → SNMP Configuration → SNMP Traps or device Properties → device Configuration → SNMP.

    2. Select the Security Log Failure Trap to configure one or more profiles for the traps to be sent to, then click Apply.

    Trellix ESM sends SNMP traps to the SNMP profile recipient with the message Failed to write to the security log.

  5. Configure an SNMP trap so that the alarm notifies when the audit functions (such as the database, cpservice, IPSDBServer) start or shut down.

  6. Select SNMP traps or SNMP Settings and click Database Up/Down Traps.

  7. Configure one or more profiles for the traps to be sent to and click Apply.

  8. Trigger an alarm when an administrative session exists for each of the defined administrative roles.

    1. Create an Internal Event Match alarm matching on Signature ID.

    2. Enter the Values for:

      • Audit Administrator - 306–38

      • Crypto-Administrator - 306–39

      • Power User - 306–40