The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use SFTP to retrieve logs

Prev Next

Configure the Trellix Enterprise Security Manager - Enterprise Log Manager to allow SFTP access to retrieve logs.

You must have ELM SFTP Access rights.

  1. Open an SFTP client such as WinSCP 5.11, Filezilla, CoreFTP LE, or FireFTP.

  2. Connect to the Trellix Enterprise Security Manager - Enterprise Log Manager using its IP address and the configured SFTP port.

    Note

    The date indicates when the system inserted the log to the Trellix Enterprise Security Manager - Enterprise Log Manager.

    The files are presented in two ways: 1) by data source then data and 2) by date then data source.

  3. Select the logs and transfer them. Specific steps to accomplish this vary based on the SFTP client you are using.

    Important

    Maximum number of files for SFTP transfers is 20,000.