The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a Syslog notification profile to forward alerts

Prev Next

You can add notification profiles that will be displayed in the Syslog page.

  1. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png in the Syslog page.

    The Add a Syslog Notification Profile page is displayed.

  2. Specify your options in the corresponding fields.

    Syslog_notification_IPSEvents.png

    Field

    Description

    Admin Domain

    • Current — Send notifications for alerts in the current domain. Always enabled for current domain by default.

    • Children — Include alerts for all child domains of the current domain

    Notification Profile Name

    Profile name from where notifications are sent

    Target Server

    Choose the target server from the drop-down to which notifications are forwarded.

    Facility

    Standard syslog prioritization value. The choices are as follows:

    • Security/authorization (code 4)

    • Security /authorization (code 10)

    • Log audit (note 1)

    • Log alert (note 1)

    • Clock daemon (note 2)

    • Local user 0 (local0)

    • Local user 1 (local1)

    • Local user 2 (local2)

    • Local user 3 (local3)

    • Local user 4 (local4)

    • Local user 5 (local5)

    • Local user 6 (local6)

    • Local user 7 (local7)

    Severity Mappings

    You can map each severity (Informational, Low, Medium, or High) to one of the standard syslog severities listed below:

    • Emergency — System is unusable

    • Alert — Action must be taken immediately

    • Critical — Critical conditions

    • Error — Error conditions

    • Warning — Warning conditions

    • Notice — Normal but significant condition

    • Informational — Informational messages

    • Debug — Debug-level messages

    Notify for All Alerts

    By default, this checkbox will be selected. Notifies for all discovered attacks.

    The following field is enabled only on deselecting the Notify for All Alerts checkbox.

    Only Notify When

    The attack definition has this notification option explicitly enabled

    Send notification for attacks that match customized policy notification settings, which you must set when editing attack responses within the policy editor (Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types) → IPS based on the following filters:

    • Severity High — Includes only high severity alerts

    • Severity Informational and above — Includes all alerts

    • Severity Low and above — Includes low, medium, and high severity alerts

    • Severity Medium and above — Includes both medium and high severity alerts

    Notify on Quarantine Events

    Select this checkbox to see quarantine events.

    Message

    The default message is a quick summary of an alert with the following fields for easy recognition: Device Name, Direction, Attack Name, Attack Severity, Attacker IP: Attacker Port, Target IP: Target Port, and Result. A default message reads:

    $IV_SENSOR_NAME$ detected $IV_DIRECTION$ attack $IV_ATTACK_NAME$ (severity = $IV_ATTACK_SEVERITY$). $IV_SOURCE_IP$:$IV_SOURCE_PORT$ -> $IV_DESTINATION_IP$:$IV_DESTINATION_PORT$ (result = $IV_RESULT_STATUS$)

    Type a message and select (click) the parameters for the wanted alert identification format. You can type custom text in the Message field.

    Message_Syslog.png

    A few important points to consider:

    • For syslog message to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each parameter. Example: $ATTACK_TIME$

    • From the 11.1 Update 9 release, $IV_MANAGER_DETAILS$ is introduced to display the hostname and IP addresses of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

    • From the 11.1 Minor 6 release, the IPS Manager can send 16384 bytes in a single syslog message.

    • Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

      As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

    • Prior to Sensor software version 10.1.5.116, the variables $IV_MALWARE_FILE_SHA1_HASH$ and $IV_MALWARE_FILE_SHA256_HASH$ do not display the file hashes.

  3. Click Save.

    The newly added notification profile will be displayed in the Syslog page.

    Syslog variables for alert notification and the equivalent Attack Log columns

    Syslog variable name

    Description

    Attack Log column

    $IV_ADMIN_DOMAIN$

    The domain to which the Sensor that detected the attack belongs

    Domain

    $IV_ALERT_ID$

    The globally unique ID that the Manager assigns to an alert

    Alert ID

    $IV_ALERT_TYPE$

    The Sensor decides the type of alert. This is mainly used by the Manager for its internal processing. This is not related to the Attack Category or Attack Sub-category. Some example alert types are signature, statistical anomaly, threshold anomaly, port scan, and host sweep.

    Not available

    $IV_APPLICATION_PROTOCOL$

    The application-layer protocol associated with the attack traffic. This is not related to the Application Identification feature, and this information is displayed even if you have not enabled Application Identification. There could be instances when a Sensor might not be able to detect the protocol.

    Not available

    $IV_ATTACK_CONFIDENCE$

    This is a value between 1 and 7. For example, a confidence level of 7 indicates that there is low possibility of the attack being a false-positive.

    The attack confidence values are inversely related to the Benign Trigger Probability (BTP) values of attack signatures.

    • Confidence 1 = BTP 7 (high)

    • Confidence 2 = BTP 6 (high)

    • Confidence 3 = BTP 5 (medium)

    • Confidence 4 = BTP 4 (medium)

    • Confidence 5 = BTP 3 (medium)

    • Confidence 6 = BTP 2 (low)

    • Confidence 7 = BTP 1 (low)

    Note

    When the BTP value is 0, there is no corresponding confidence value for the attack.

    Not available

    $IV_ATTACK_COUNT$

    The number of types the attack occurred. This information is more relevant for suppressed alerts. Consider you have enabled alert suppression such that the alert is raised only when the attack is seen 5 times within 30 seconds. Subsequently, the Sensor detected this attack 10 times within 30 seconds. Then the attack count for this alert is 10.

    Attack Count

    $IV_ATTACK_ID$

    Trellix Advanced Research Center assigns a universally unique hexadecimal value to each attack. This field displays the integer value of the hexadecimal ID assigned by Trellix ARC.

    The equivalent hexadecimal value is displayed in the Attack Information & Description page as Intruvert ID.

    $IV_ATTACK_NAME$

    The name assigned by Trellix ARC to an attack

    Name

    $IV_ATTACK_SEVERITY$

    Indicates the severity value of an attack specified in the corresponding attack definition.

    • 0 - Informational

    • 1 to 3 - low

    • 4 to 6 - medium

    • 7 to 9 - high

    Attack Severity (high, medium, low, or informational)

    $IV_ATTACK_SIGNATURE$

    The ID of the signature that matched the attack traffic

    Not available

    $IV_ATTACK_TIME$

    The time when the Sensor created the alert

    Time

    $IV_CALLBACK_ACTIVITY$

    The name of the Callback Activity family

    Callback Activity

    $IV_CATEGORY$

    The category to which the attack belongs. This is decided by Trellix ARC. Some examples are exploit, policy violation, and reconnaissance. You can view the attack categories in the IPS Policy Editor when you group by Attack Category.

    Attack Category

    $IV_CC_DOMAIN$

    The name of the Callback Activity domain

    C&C Domain

    $IV_DESTINATION_CRITICALITY$

    Displays the risk level as High Risk, Medium Risk or Low Risk

    Target Risk

    $IV_DESTINATION_IP$

    The destination IP address to which the attack is destined

    Target IP address

    $IV_DESTINATION_NAME $

    The name of the host to which the attack is destined

    Target Hostname

    IV_DESTINATION_PORT$

    The port number on the destination host to which the attack traffic is sent

    Target Port

    $IV_DESTINATION_PROXY_IP

    The IP address of the proxy server

    Target Proxy IP

    $IV_DEST_APN$

    This is the destination Access Point Name (APN). This information is part of a mobile subscriber's identity data and is relevant only if you have deployed Sensors to monitor mobile networks. To see this data, you must enable capturing and tagging of mobile subscriber data in the alerts by using the set mnsconfig Sensor CLI command.

    Not available

    $IV_DEST_IMSI$

    This is the destination International Mobile Subscriber Identity (IMSI). The details provided for APN apply to this as well.

    Not available

    $IV_DEST_OS$

    The operating system installed on the destination host

    Target OS

    $IV_DEST_PHONE_NUMBER$

    This is the destination mobile phone number. The details provided for APN above apply to this as well.

    Not available

    $IV_DETECTION_MECHANISM$

    The method the Sensor used to detect the attack. For example, signature, multi-flow-correlation, threshold, and so on. Each method relates to a specific attack category.

    Detection (in Alert Details panel)

    $IV_DEVICE_ALERT_UUID$

    ID assigned to the alert

    Alert ID

    $IV_DEVICE_NAME$

    Name of the device that detected the attack

    Device

    $IV_DIRECTION$

    Indicates whether the attack traffic originated from your network or the outside network. For example, inbound direction means that the attack traffic originated from the outside network, targeting the hosts on your network.

    Direction

    $IV_INTERFACE$

    The interface or sub-interface on which the Sensor detected the attack traffic

    Interface

    $IV_LAYER_7_DATA$

    Provides the Layer 7 data

    Layer 7 Data

    $IV_MALWARE_CONFIDENCE$

    Confidence level of the malware as detected by the engine

    Malware Confidence

    $IV_MALWARE_DETECTION_ENGINE$

    Engine which detected the malware (Gateway Anti-Malware, Global Threat Intelligence, PDF‑JS, etc)

    Engine

    $IV_MALWARE_FILE_LENGTH$

    The length of the malware file

    Not available

    $IV_MALWARE_FILE_MD5_HASH$

    The MD5 hash of the malware file (fingerprint)

    File Hash

    $IV_MALWARE_FILE_NAME$

    The name of the malware file. For SMTP traffic, it displays the file name of the attachment and for HTTP traffic, it displays the URL of the file.

    File Name

    $IV_MALWARE_FILE_SHA1_HASH$

    The SHA1 hash of the malware file (fingerprint)

    File Hash

    $IV_MALWARE_FILE_SHA256_HASH$

    The SHA256 hash of the malware file (fingerprint)

    File Hash

    $IV_MALWARE_FILE_TYPE$

    The file type of the malware file

    Not available

    $IV_MALWARE_VIRUS_NAME$

    The virus name as detected by Gateway Anti-Malware

    Not available

    $IV_MANAGER_DETAILS$

    The hostname and IP address of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

    Not available

    $IV_MEMBER_DEVICE_NAME$

    Name of the device that detected the attack

    Device

    $IV_NETWORK_PROTOCOL$

    The network protocol, such as TCP, of the attack traffic

    Protocol (in Alert Details panel)

    $IV_QUARANTINE_END_TIME$

    The time when the attacking host will be out of quarantine. This is relevant only if you had enabled Quarantine feature.

    Not available

    $IV_RELEVANCE$

    Indicates if the endpoint is vulnerable to this particular attack

    Relevance

    $IV_RESULT_STATUS$

    Indicates whether the attack traffic reached the victim host

    Result

    $IV_SOURCE_CRITICALITY$

    Displays the risk level as High Risk, Medium Risk or Low Risk

    Attacker Risk

    $IV_SENSOR_ALERT_UUID$

    The universally unique ID assigned by the Sensor for the alert. For a specific alert raised by a specific Sensor, the Central Manager also displays the same ID.

    Alert ID

    $IV_SENSOR_CLUSTER_MEMBER$

    The member Sensor of a HA pair that generated the alert

    Not available

    $IV_SENSOR_NAME$

    The Sensor that generated the alert

    Device

    $IV_SOURCE_IP$

    The IP address of the attacking host

    Attacker IP address

    $IV_SOURCE_NAME$

    Name of the host from where the attack was generated

    Attacker Hostname

    $IV_SOURCE_OS$

    OS of the attacking host

    Attacker OS (in Alert Details panel)

    $IV_SOURCE_PORT$

    The port number on the attacking host from which the attack traffic is sent

    Attacker Port

    $IV_SOURCE_PROXY_IP$

    The IP address of the proxy server

    Attacker Proxy IP

    $IV_SOURCE_VM_NAME$

    Name of the virtual machine from where the attack was generated

    Attacker VM Name

    $IV_SRC_APN$

    This is the source Access Point Name (APN). This information is part of a mobile subscriber's identity data and is relevant only if you have deployed Sensors to monitor mobile networks. To see this data, you must enable capturing and tagging of mobile subscriber data in the alerts by using the set mnsconfig Sensor CLI command.

    Not available

    $IV_SRC_IMSI$

    This is the source International Mobile Subscriber Identity (IMSI). The details provided for APN apply to this as well.

    Not available

    $IV_SRC_PHONE_NUMBER$

    This is the source mobile phone number. The details provided for APN apply to this as well.

    Not available

    $IV_SUBTECHNIQUE$

    Name of the corresponding adversarial sub-technique matching with the attack or alert

    Sub-Technique

    $IV_SUB_CATEGORY$

    The subcategory to which the attack belongs. This is decided by Trellix ARC, and is a classification within Attack Category. Some examples are brute-force, buffer-overflow, host-sweep, and restricted-application. You can view the attack subcategories in the IPS policy editor when you group by Attack Subcategory.

    Attack Subcategory (in Alert Details panel)

    $IV_TACTIC$

    Name of the adversarial tactic matching with the attack or alert

    Tactic

    $IV_TARGET_VM_NAME$

    Name of the virtual machine to which the attack is directed

    Target VM Name

    $IV_TECHNIQUE$

    Name of the corresponding adversarial technique matching with the attack or alert

    Technique

    $IV_TTPID$

    ID of the specific technique/sub-technique in the<techniqueID.sub-techniqueID> format

    Technique/Sub-Technique ID

    $IV_VLAN_ID$

    The VLAN ID seen on the attack traffic

    VLAN



    Note

    Mitre Attack Details can be currently forwarded through the Manager alone. So, if you plan to forward details such as the Tactic, Technique, Sub-Technique, or Technique/Sub-Technique ID, you need to assign the relevant variables only through this page.