The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

auditlogupload

Prev Next

This command uploads the audit log file to the configured TFTP/SCP server. This file can contain a maximum of 5000 recent audit events.

Syntax:

auditupload WORD

auditlogupload tftp WORD

auditlogupload scp WORD

where WORD stands for the name of the audit log file to be uploaded.

Note the following:

  • When loading an audit log file on the SCP server, you are prompted for the SCP server credentials (username and password). The command succeeds only on providing the correct SCP server credentials.

  • When loading an audit log file on the SCP server, the pathname of the file should be absolute. When loading from the TFTP server, the pathname of the file should be relative to /tftpboot.

  • If no filename is specified, the default filename is created in the specified path on the SCP server. The default file name for the audit log is audit_<sensor_timestamp>_<sensor_name>.log.

  • Before executing this command (uploading on the TFTP server), make sure that the file is created on the TFTP server with write permissions for everyone.

  • The functionality of auditlogupload tftp WORD is the same as auditupload WORD.

Applicable to:

NS-series Sensors