The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure SNMP and Syslog servers

Prev Next

The Manager → <Admin Domain Name> → Setup → Notification → Server Configuration page in the Manager and Central Manager allows you to configure the Syslog and SNMP servers. These servers are then used in configuring Syslog and SNMP notifications in IPS Events, Faults, and User Activity.

Sever Configuration
Sever Configuration


Callout

Description

1

Tabs namely, Syslog and SNMP

2

Top-right menu

3

Grid view

4

Bottom-left menu

The following options are available in the tabs of the Server Configuration page:

Options

Description

Top-right menu

Quick Search

Enter the keyword in the Quick Search field and the results are automatically displayed.

GUID-B8353911-03AF-4623-BB6C-F702E5BC9711-low.jpg

Refreshes the tab.

Bottom-left menu

GUID-8D2203E5-2C86-4970-8BBE-0E051DDA1A11-low.jpg

Add new servers.

GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg

Delete existing servers.

You can delete only one server at a time.

A Deleted notification appears in case of successful deletion. Else, an Error dialog-box appears stating the reason for unsuccessful deletion.

Note

If you are upgrading the Manager to 11.1 Update 2 or later software versions, the Manager automatically lists any existing SNMP and Syslog servers under the respective tabs in this page. The server profile name is automatically assigned by the Manger in this format <Domain Name><event/fault/audit><profile number>. For example, you are upgrading the Manager from 11.1.7.3 to 11.1.7.41. The SNMP servers are configured for the admin domain named IPS-Denver and two child domains named IPS-Welton and IPS-Larimer. IPS-Denver has 3 existing profiles while IPS-Welton and IPS-Larimer have 2 existing profiles.

When you upgrade the Manager to 11.1.7.41 or later versions, this configuration is automatically mapped under the SNMP tab under each domain. User accessing the admin domain named IPS-Denver will be viewing the server profile names as IPS-Denverfault1, IPS-Denverfault2, and IPS-Denverfault3. User accessing the child domain IPS-Welton will be viewing 2 server profiles IPS-Weltonfault1 and IPS-Weltonfault2. Similarly, user accessing the child domain IPS-Larimer will be viewing 2 server profiles IPS-Larimerfault1 and IPS-Larimerfault2.

User accessing one domain will not be able to view the servers created in other domains.

In case user has used the same Syslog or SNMP server for IPS Events, Faults, and User Activity, three server profiles will created under the SNMP and Syslog tabs. Users can opt to delete the duplicate entries and have only one entry assigned to all the profiles. Before deleting the duplicate entries, ensure that the associated servers are not attached to any of the Syslog or SNMP notification profiles.

Note

Before upgrading the Manager to 11.1 Update 2 or later software versions, if user has created a Syslog server (under IPS Events page) at admin domain level and same server is used in child domains, post upgrade, the user sees profiles with the same name at both admin and child domain levels. In this case, if the user plans to remove one of the profiles from any of the domains and tries creating or updating a profile with the old name in the same domain or any other domain, an error is displayed stating the name is already in use.