The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Set up database audit trails

Prev Next

Set up an audit trail to track access and changes made to the database or to tables associated with specific database events. The Trellix ESM compliance report lists audit trails associated with each event.

To generate audit trail events, you must add:

  • Data Access rules

  • Privileged User Audit Trails report

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Policy Editor.

  2. In the Rule Types pane, select DEM → Data Access.

  3. Highlight DEM - Template Rule - Trusted Use Access From IP Range.

  4. Click Edit → Copy, then click Edit → Paste.

  5. Change the name and properties of the new rule.

    1. Highlight the rule, then select Edit → Modify.

    2. Name the rule, then type the user name.

    3. Select the Untrusted action type, then click OK.

  6. Click the Rollout icon GUID-A5690870-A648-4CC7-B1B1-F092A03B5C3B-low.png.

  7. Set up the report:

    1. On System Properties, click Reports → Add.

    2. Fill in sections 1–3, and 6.

    3. In section 4, select Report PDF or Report HTML

    4. In section 5, select Compliance → SOX → Privileged User Audit Trails (Database).

    5. Click Save.

  8. To generate the report, click Run Now.