The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure a Syslog server

Prev Next

You can add, edit, or delete a Syslog server from the Syslog tab.

Steps:

  1. To add a Syslog server, go to the Syslog tab and click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon at the bottom-left corner of the page.

    The Syslog Server Configuration Details panel opens to the right of the page.

    GUID-D9CF5E81-4C54-47F2-B902-02D466349941-low.png
  2. Specify your options in the appropriate fields.

    Field

    Description

    Target Server Profile Name

    Specify a profile name for the server addition. This name will be used while configuring the Syslog notification profile.

    Note

    It is recommended to specify the Server Profile Name as <DomainName>_<ServerProfileName> to avoid confusing with child domains names.

    Server Name or IP Address

    The server name or IP address of the target Syslog server. The IP address should be IPv4.

    Protocol

    The protocol used. This can be TCP/UDP.

    Port

    The listening port of the target server

    The following options appear only when TCP Protocol is selected.

    Use SSL

    If you are selecting this check-box, you need to provide a certificate for SSL communication.

    Certificate File

    Click Browse to select the certificate. Upon selecting the certificate, click Import. The supported certificate file format is .pem.

    GUID-0D8733B4-171B-4F9B-88BD-37F73CB6D2F6-low.png

    Current Certificate

    Displays the imported/existing certificate content.

    Test Connection

    Click Test Connection to check if the connection is successful. If a TCP server is down, at least five attempts will be made to ping the server before a fault is raised.

  3. Click Save.

    The Syslog server is added under the Syslog tab.

  4. If you want to modify an existing entry, double-click the specific Syslog entry. The Syslog Server Configuration Details panel opens where you can update the required fields and save the changes.

  5. In case you want to delete an existing server, select the specific entry and click GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg. You can delete only one server entry at a time.

Important

From the 11.1 Minor 6 release, you can configure the syslog server timeout value in minutes using 'notifications.syslog.tcptimeout'. When 'notifications.syslog.tcptimeout' is configured, the Manager reconnects to the syslog server at given intervals. If the time since the last connection re-establishment to the syslog server exceeds the configured timeout, the Manager will re-establish the connection before sending the syslog message. However, if 'notifications.syslog.tcptimeout' is not configured, the Manager will not reconnect once the trust has been established. After configuring 'notifications.syslog.tcptimeout', you must restart the Manager service for the changes to take effect.

You can customize the timeout value by navigating to the <Manager_Install_Dir>\App\Config folder. If the 'advanced-config.properties' file does not exist, create it. Then, add 'notifications.syslog.tcptimeout' and specify the timeout value in minutes.

Example: notifications.syslog.tcptimeout = 5