The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Appendix: Audit Log Records

Prev Next

This section describes the audit log records in relation to a user's activities. The general format of audit records is:

Timestamp, Appliance Name, Process/Function, Message

An example of an audit record is:

NSMAppliance sshd[3694]: Disconnecting: Too many authentication failures [preauth]

When displayed in the GUI, this information is further broken out into:

Date, Admin Domain, User, Attack Category, Action, Result, Description

An example of an audit record displayed in the GUI is:



The following table documents the messages within audit log records generated by Trellix Intrusion Prevention System.

Audit Log Records
Action Log Message
Changes to the system time by an Administrator Time has been changed
Communication between the Manager and Sensors
  • Enabling: Successfully added sensor "sensor_name"
  • Disabling: Successfully deleted sensor "sensor_name"
Failure to establish a TLS Session
  • Certificate having missing Extended keys
  • Mismatch between configured Server Name and Subject Alt Name in Imported certificate
  • The connection to syslog server IP_Address:port_number failed. Error: Syslog TCP connection failed.
Failure to establish an HTTPS Session Mismatch between configured Server Name and Subject Alt Name in Imported certificate
Failure to establish an SSH session
  • Disconnecting: Too many authentication failures [preauth]
  • Unable to negotiate with IP_Address port port_number: no matching host key type found. Their offer: host_key_type [preauth]
  • Unable to negotiate with IP_Address port port_number: no matching key exchange method found. Their offer: key_exchange_method [preauth]
Management activities of system data
  • Read audit log
  • Successfully set Session Timeout
  • Logon Banner Configuration updated
  • Successfully set Password Content, Configuration is …
Trusted connections
  • Initiation:
    • Pktlog Channel back up. Clear the Pktlog Channel Down event of sensor sensor
    • Alert Channel back up. Clear the Alert Channel Down event of sensor sensor
    • Syslog Client - Added to Retry Q
    • Syslog Client - Flushing and Shutting down
    • Request for Authentication for User name=Username
  • Termination:
    • The link on Port: Port_identifier is Down Count: number. The link between this port and the external device to which it is connected is down.
    • Received disconnect from IP_Address port port_number: disconnected by user
    • User "User Name" with login id "Username" logged off Trellix IPS Manager from "Hostname (IP_Address)"
  • Failure:
    • Certificate having missing Extended keys
    • Mismatch between configured Server Name and Subject Alt Name in Imported certificate
    • Received fatal alert: handshake_failure
    • Connection refused (Connection refused)
    • Disconnecting: Too many authentication failures [preauth]
    • Unable to negotiate with IP_Address port port_number: no matching host key type found. Their offer: hostkey_type [preauth]
    • Unable to negotiate with IP_Address port port_number: no matching key exchange method found. Their offer: key_exchange_method [preauth]
Unsuccessful attempt to validate an X.509 certificate
  • Certificate having missing Extended keys
  • Mismatch between configured Server Name and Subject Alt Name in Imported certificate
Unsuccessful login attempts limit is met or exceeded Login failed: Maximum allowable login attempts number have exceeded
Use of the identification and authentication mechanism
  • Postponed keyboard-interactive/pam for username from IP_Address port port_number ssh2 [preauth]
  • Postponed publickey for username from IP_Address port port_number ssh2 [preauth]
  • Accepted keyboard-interactive/pam for username from IP_Address port port_number ssh2
  • error: Could not load host key: path_to_hostkey_file
  • Failed keyboard-interactive/pam for username from IP_Address port port_number ssh2
  • Failed publickey for username from IP_Address port port_number ssh2: RSA SHA256:public_key_value
  • User "username" failed to log in to Trellix IPS Manager from "Hostname (IP_Address)". Login URI: /intruvert/jsp/module/Login.jsp. URI referrer : https://Hostname//intruvert/jsp/module/Login.jsp , protocol : HTTP/1.2
  • Unknown login ID "Username". Login failed from "Hostname (IP_Address)". Login URI: /intruvert/jsp/module/Login.jsp. URI referrer : https://Hostname//intruvert/jsp/module/Login.jsp , protocol : HTTP/1.2
  • Starting Session number of user Username
  • Trellix IPS Manager Login failed at timestamp
User session terminated
  • · Removed session number.
  • User "User Name" with login id "Username" logged out of the Manager from "Hostname (IP_Address)".
  • Close session: user Username from IP_Address port port_number id number