The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Track administrative and user activity in ePO SaaS with the Audit Log

Prev Next

The Audit Log workspace provides centralized visibility to trace administrative, user, and system events across the Trellix ePO - SaaS platform. With a modernized interface, administrators can review and investigate activities across the ePO - SaaS platform and troubleshoot issues faster.

With Audit Log, you can:

Note

The Audit Log is currently available to customers in the US and EU regions only.

Investigate activity in the Audit log

Filter entries by time range, product suite, or saved query criteria to identify specific system actions across your environment.

Prerequisites

Ensure you are assigned a role with permissions to view ePO - SaaS reports.

  1. Select Menu → Reporting → Audit Log (New).

  2. Review the activity logs in the table based on the selected time range.

    Option

    Description

    Event Summary

    Identifies the event category and type.

    Actor Summary

    Identifies the ID, name, and account type of the user or service.

    Action Summary

    Identifies the action name and operation type.

    Affected Resource Summary

    Displays the impacted resource types and total count.

    Action Interval

    Identifies the start time, end time, and execution duration.

    Action Detail Summary

    Displays the system descriptive message.

    Action Severity

    Displays the Low or High severity level indicator.

    Affected Resource Summary

    Displays the resource ID, resource count, resource type, and resource name affected by the change. For logs involving a policy or configuration change, click View more to view a side-by-side comparison showing exactly what was modified.

  3. You can further filter the list by applying below filters:

    • Time Range: Select a preset range or select Custom to specify UTC dates.

    • Provider Suite and Provider App: Select a specific Trellix product suite or module.

    • Basic Filter: Enable the toggle and select a saved filter set.

    • Refresh: Click Refresh at the top right to load the newest entries. This also updates the Provider App list with the latest available options for your tenant.

  4. Click a column header to sort table entries. For multi-field columns such as Action Interval, select Start Time, End Time, or Execution Time to sort.

Build custom filters for detailed investigations

Create a customized filter to perform specific administrative or user actions.

  1. Select Menu → Reporting → Audit Log (New).

  2. Select Match All to enforce all criteria, or select Match Any to enforce at least one.

  3. Click + Add Filter. The toggle switches from Basic Filter to Advanced Filters automatically.

  4. Configure the filter parameters:

    • Select Attribute: Choose the target database attribute.

    • Select Operator: Choose the evaluation operator.

    • Select Value: Enter or select the target value.

  5. Click + Add Filter again to add more conditions.

  6. Click Apply to execute the filter, or click Save to save the filter for reuse. Click Clear All to remove all conditions.

  7. To search for specific text within an attribute, click + Add Filter, select the attribute you want to search, select = equals as the operator, then enter the value to match. Example: To find entries containing specific text in the action message, select Action Message as the attribute, then enter the text you want to search for. This filters entries where the Action Detail Summary column matches.

Customize your Audit Log display view

Modify log table columns to focus on details relevant to your investigation.

  1. Select Menu → Reporting → Audit Log (New).

  2. Click the table settings icon and select Customize Columns to open the Primary Audit Columnset panel.

  3. Click Save to update the current view, click Save As to create a named layout, or click Reset to restore default columns.

  4. Click the table settings icon and select Hide Empty Columns to remove fields containing no data.

  5. Select an item from the Columnset drop-down menu to switch between saved layouts.