The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Syslog Forwarder

Prev Next

The User Activity option enables the forwarding of Trellix IPS audit information to a syslog server. Syslog forwarding enables you to view the forwarded audit information via a third-party syslog application. For syslog forwarding, the root domain and parent domains have the option to include audit information from all corresponding child domains. To enable syslog forwarding for audit notification, do the following:

Task

  1. Select Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog.
    The Syslog page is displayed.
  2. Fill in the following fields:
    Field Description
    Enable Syslog Notification Yes is enabled; No is disabled
    Admin Domain
    • Current— Send notifications for audit information in the current domain. Always enabled for current domain.
    • Children— Include audit information for all child domains of the current domain.
    Server Name or IP Address Type either the Host IP Address or Server Name of the syslog server where audit information will be sent.

    For Host IP address, you can enter either IPv4 or IPv6 address.

    Note

    The length of server name has been increased to support up to 255 characters from 40 characters.

    Protocol Select TCP or UDP from the drop-down list.

    Note

    If you select the TCP protocol, you will have to provide a certificate when you select the Use SSL checkbox.

    Port Port on the target server which is authorized to receive syslog messages. The standard port for syslog, 514, is pre-filled in the field.
    Facilities Standard syslog prioritization value. The choices are as follows:
    • Security/authorization (code 4)
    • Security/authorization (code 10)
    • Log audit (note 1)
    • Log alert (note 1)
    • Clock daemon (note 2)
    • Local user 0 (local0)
    • Local user 1 (local1)
    • Local user 2 (local2)
    • Local user 3 (local3)
    • Local user 4 (local4)
    • Local user 5 (local5)
    • Local user 6 (local6)
    • Local user 7 (local7)
    Result Mapping You can map each audit result (Failed to, Successful to, and In Progress to) to one of the standard syslog severities listed below (default result severities are noted in parentheses):
    • Emergency— System is unusable
    • Alert— Action must be taken immediately
    • Critical— (HIGH) Critical conditions
    • Error— Error conditions
    • Warning— (MEDIUM) Warning conditions
    • Notice— (LOW) Normal but significant condition
    • Informational— (INFORMATIONAL) Informational message
    • Debug— Debug-level messages
    Forward Audit Select the severity of the audit that you want to be forwarded to the syslog server. The options are:
    • Allow all Auditlogs
    • Failed only
    • Successful only
    • In Progress only
    Message Preference Select the preference of the message. The options are:
    • System default— This is available by default
    • Customized— This is available once the notification is enabled
  3. Click Apply.