This section describes the audit log records in relation to a user's activities. The general format of audit records is:
Time,Results,Category,Summary,Details,Domain,UserDate, Admin Domain, User, Attack Category, Action, Result, Description
An example of an audit record displayed in the GUI is:

The following table documents the messages within audit log records generated by Trellix Intrusion Prevention System.
Action | Log Message |
|---|---|
Changes to the system time by an Administrator | Time has been changed |
Communication between the Manager and Sensors |
|
Failure to establish a TLS Session |
|
Failure to establish an HTTPS Session | Mismatch between configured Server Name and Subject Alt Name in Imported certificate |
Failure to establish an SSH session |
|
Management activities of system data |
|
Trusted connections |
|
Unsuccessful attempt to validate an X.509 certificate |
|
Unsuccessful login attempts limit is met or exceeded | Login failed: Maximum allowable login attempts number have exceeded |
Use of the identification and authentication mechanism |
|
User session terminated |
|
Requirement | Auditable Events | Additional Audit Record Contents | Audit Logs |
|---|---|---|---|
FAU_GEN.1 |
| None |
|
FAU_GEN_EXT.1 | None | None | - |
FAU_GEN.2 | None | None | - |
FAU_STG_EXT.1 | None | None | - |
FCS_CKM.1 | None | None | - |
FCS_CKM.2 | None | None | - |
FCS_CKM.4 | None | None | - |
FCS_COP.1/DataEncryption | None | None | - |
FCS_COP.1/SigGen | None | None | - |
FCS_COP.1/Hash | None | None | - |
FCS_COP.1/KeyedHash | None | None | - |
FCS_RBG_EXT.1 | None | None | - |
FCS_TLSC_EXT.1 | Failure to establish a TLS Session | Reason for failure | ![]() |
FCS_TLSS_EXT.1 | Failure to establish a TLS Session | Reason for failure | ![]() |
FCS_TLSS_EXT.2 | Failure to establish a TLS Session | Reason for failure | ![]() |
FCO_CPC_EXT.1 |
| Identities of the endpoints pairs enabled or disabled | Enabling communications: ![]() Disabling communications: ![]() |
FIA_AFL.1 | Unsuccessful login attempts limit is met or exceeded. | Origin of the attempt (e.g., IP address). | Web GUI: ![]() SSH: ![]() ![]() |
FIA_PMG_EXT.1 | None | None | - |
FIA_UIA_EXT.1 | All use of the identification and authentication mechanism | Origin of the attempt (e.g., IP address) | Console: ![]() ![]() SSH: ![]() ![]() Web GUI: ![]() ![]() |
FIA_UAU_EXT.2 | All use of the identification and authentication mechanism | Origin of the attempt (e.g., IP address) | Console: ![]() ![]() SSH: ![]() ![]() Web GUI: ![]() ![]() |
FIA_UAU.7 | None | None | - |
FIA_X509_EXT.1/Rev | Unsuccessful attempt to validate a certificate | Reason for failure | ![]() |
FIA_X509_EXT.1/ITT | Unsuccessful attempt to validate a certificate | Reason for failure | ![]() |
FIA_X509_EXT.2 | None | None | - |
FIA_X509_EXT.3 | None | None | - |
FMT_MOF.1/ManualUpdate | Any attempt to initiate a manual update | None | ![]() |
FMT_MTD.1/CoreData | None | None | - |
FMT_SMF.1 | All management activities of TSF data. | None | Refer to the below table Manager Management Functions |
FMT_SMR.2 | None | None | - |
FPT_APW_EXT.1 | None | None | - |
FPT_ITT.1 |
| Identification of the initiator and target of failed trusted channels establishment attempt | Initiation of trusted channel: ![]() Termination of trusted channel: ![]() Failure of trusted channel functions: ![]() |
FPT_SKP_EXT.1 | None | None | - |
FPT_STM_EXT.1 | Discontinuous changes to time - either Administrator actuated or changed via an automated process | For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address) | ![]() |
FPT_TST_EXT.1 | None | None | - |
FPT_TUD_EXT.1 | Initiation of update; result of the update attempt (success or failure) | None | ![]() |
FTA_SSL_EXT.1 | The termination of a local session by the session locking mechanism | None | ![]() |
FTA_SSL.3 | The termination of a remote session by the session locking mechanism | None | SSH: ![]() Web GUI: ![]() |
FTA_SSL.4 | The termination of an interactive session | None | SSH: ![]() WebGUI: ![]() Console: ![]() |
FTA_TAB.1 | None | None | - |
FTP_ITC.1 |
| Identification of the initiator and target of failed trusted channels establishment attempt | Initiation of the trusted channel: ![]() Termination of the trusted channel: ![]() Failure of the trusted channel functions: ![]() |
FTP_TRP.1/Admin |
| Identification of the claimed user identity. | Initiation of trusted channel SSH: ![]() Web GUI: ![]() Termination of the trusted channel: SSH: ![]() Web GUI: ![]() Failure of trusted channel functions: SSH: ![]() Web GUI: ![]() |
FAU_STG_EXT.4 | None | None | - |
FCS_HTTPS_EXT.1 | Failure to establish a HTTPS Session | Reason for failure | ![]() |
FCS_SSHS_EXT.1 | Failure to establish an SSH session | Reason for failure | ![]() |
Management Functions | Test cases |
|---|---|
Ability to administer the TOE locally and remotely | Console: ![]() SSH: ![]() WebGUI: ![]() |
Ability to configure the access banner | ![]() |
Ability to configure the session inactivity time before session termination or locking | ![]() |
Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates | Positive update: ![]() Negative update: ![]() |
Ability to configure the authentication failure parameters for FIA_AFL.1 | ![]() |
Ability to configure audit behaviour (e.g. changes to storage locations for audit; changes to behaviour when local audit storage space is full); | ![]() ![]() |
Ability to modify the behaviour of the transmission of audit data to an external IT entity | ![]() |
Ability to configure the cryptographic functionality | ![]() |
Ability to import X.509v3 certificates to the TOE's trust store | ![]() |
Ability to set the time which is used for timestamps | ![]() |
Ability to re-enable an Administrator account | ![]() |
Ability to manage the trusted public keys database | ![]() |
Ability to configure the interaction between TOE components | ![]() ![]() |
Requirement | Auditable Events | Additional Audit Record Contents | Audit Logs |
|---|---|---|---|
FAU_GEN.1 |
| None |
|
FAU_GEN.1/IPS | None | None | - |
FAU_GEN_EXT.1 | None | None | - |
FAU_GEN.2 | None | None | - |
FAU_STG_EXT.5 | None | None | - |
FCS_CKM.1 | None | None | - |
FCS_CKM.2 | None | None | - |
FCS_CKM.4 | None | None | - |
FCS_COP.1/DataEncryption | None | None | - |
FCS_COP.1/SigGen | None | None | - |
FCS_COP.1/Hash | None | None | - |
FCS_COP.1/KeyedHash | None | None | - |
FCS_RBG_EXT.1 | None | None | - |
FCS_SSHC_EXT.1 | Failure to establish an SSH session | Reason for failure | ![]() |
FCS_SSHS_EXT.1 | Failure to establish an SSH session | Reason for failure | ![]() |
FCS_TLSC_EXT.2 | Failure to establish a TLS Session | Reason for failure | ![]() |
FCO_CPC_EXT.1 |
| Identities of the endpoints pairs enabled or disabled | Enabling communications: ![]() Disabling communications: ![]() ![]() |
FIA_AFL.1 | Unsuccessful login attempts limit is met or exceeded. | Origin of the attempt (e.g., IP address). | ![]() |
FIA_PMG_EXT.1 | None | None | - |
FIA_UIA_EXT.1 | All use of the identification and authentication mechanism | Origin of the attempt (e.g., IP address) | Console: ![]() ![]() SSH: ![]() ![]() |
FIA_UAU_EXT.2 | All use of the identification and authentication mechanism | Origin of the attempt (e.g., IP address) | Console: ![]() ![]() SSH: ![]() ![]() |
FIA_UAU.7 | None | None | - |
FIA_X509_EXT.1/ITT | Unsuccessful attempt to validate a certificate | Reason for failure | ![]() |
FIA_X509_EXT.3 | None | None | - |
FMT_MOF.1/ManualUpdate | Any attempt to initiate a manual update | None | ![]() |
FMT_MTD.1/CoreData | None | None | - |
FMT_SMF.1 | All management activities of TSF data. | None | Refer to the below table Sensor Management Functions |
FMT_SMR.2 | None | None | - |
FPT_APW_EXT.1 | None | None | - |
FPT_ITT.1 |
| Identification of the initiator and target of failed trusted channels establishment attempt | Initiation of trusted channel: ![]() Termination of trusted channel: ![]() Failure of trusted channel functions: ![]() |
FPT_SKP_EXT.1 | None | None | - |
FPT_STM_EXT.1 | Discontinuous changes to time - either Administrator actuated or changed via an automated process | For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address) | ![]() |
FPT_TST_EXT.1 | None | None | - |
FPT_TUD_EXT.1 | Initiation of update; result of the update attempt (success or failure) | None | ![]() |
FTA_SSL_EXT.1 | The termination of a local session by the session locking mechanism | None | ![]() |
FTA_SSL.3 | The termination of a remote session by the session locking mechanism | None | ![]() |
FTA_SSL.4 | The termination of an interactive session | None | SSH: ![]() Console: ![]() |
FTA_TAB.1 | None | None | - |
FTP_TRP.1/Admin |
| Identification of the claimed user identity | Initiation of the trusted channel: ![]() Termination of the trusted channel: ![]() Failure of the trusted channel functions: ![]() |
FMT_SMF.1/IPS | Modification of an IPS policy element | Identifier or name of the modified IPS policy element (e.g. which signature, baseline, or known-good/known-bad list was modified) | ![]() |
IPS_ABD_EXT.1 | Inspected traffic matches an anomaly-based IPS policy |
| ![]() |
IPS_IPB_EXT.1 | Inspected traffic matches a list of known-good or known-bad addresses applied to an IPS policy |
| ![]() |
IPS_SBD_EXT.1 | Inspected traffic matches a signature-based IPS rule with logging enabled |
| ![]() |
Management Functions | Test cases |
|---|---|
Ability to administer the TOE locally and remotely | SSH: ![]() Console: ![]() |
Ability to configure the access banner | ![]() |
Ability to configure the session inactivity time before session termination or locking | ![]() |
Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates | Positive update: ![]() Negative update: ![]() |
Ability to configure the authentication failure parameters for FIA_AFL.1 | ![]() |
Ability to configure audit behaviour (e.g. changes to storage locations for audit; changes to behaviour when local audit storage space is full); | ![]() |
Ability to modify the behaviour of the transmission of audit data to an external IT entity | ![]() |
Ability to configure the cryptographic functionality | ![]() |
Ability to import X.509v3 certificates to the TOE's trust store | ![]() |
Ability to set the time which is used for timestamps | ![]() |
Ability to re-enable an Administrator account | ![]() |
Ability to manage the trusted public keys database | ![]() |
Ability to configure the interaction between TOE components | ![]() ![]() |
































































































