The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Logon Timeout

Prev Next

The logon timeout sets the number of minutes to cache unique events. The uniqueness of an event is determined by the following:

  • Source metadata (account name, host name, IP address)

  • Target metadata (account name, host name, IP address)

  • Event metadata

  • Process Path

By default, the timeout is 24 hours (1440 minutes). When the timeout is set to 0, caching is disabled.

Note

It is always recommended not to disable the cache.

Some log sources are extremely verbose, and the cache is imperative to reducing the data set on the Server. As an example, it is not uncommon to observe a Windows Server generate duplicate event logs several times within a four-hour period. The only scenario where disabling the cache can be useful is on the Agent deployments to a limited number of systems (example: in a test lab).