The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize syslog messages

Prev Next

For customizing syslog message, ensure that Enable Syslog Notification is enabled in the page.

  1. Go to, Manager → <Admin Domain Name> → Setup → Notification → Firewall Access Events.

  2. Enter the Server name or IP address.

  3. Enter the port number

Note

The page displays the message: Settings successfully saved.

Note

In Message body, the default option is selected as Customized.

After configuring the syslog forwarder, do the following steps to customize syslog message.

  1. Click Edit.

    The Customize Syslog Forwarder Message page is displayed. By default, the following audit information parameters are included in Messages:

    • audit action

    • audit result

    • audit time

    These parameters are displayed as: Audit $IV_AUDIT_ACTION$ $IV_AUDIT_RESULT$ at $IV_AUDIT_TIME$

  2. Type a message and select (click) the parameters that should be included in Message. The following are the list parameters that are available in the Message field.

    Syslog variables for audit notification

    Syslog variable name

    Description

    $IV_AUDIT_ACTION$

    The audit action value based on the action ID that was passed.

    $IV_AUDIT_RESULT$

    Indicates the stage of auditing (received, succeeded, failed, or ongoing).

    $IV_AUDIT_TIME$

    Time stamp of the audit message.

    $IV_AUDIT_MESSAGE$

    The audit message.

    $IV_AUDIT_USER$

    The username for the audit.

    $IV_AUDIT_CATEGORY$

    The action taken for the audit.

    $IV_AUDIT_DOMAIN$

    Name of the domain.

    $IV_AUDIT_DETAIL_COMMENT$

    Displays committed comments if the audit details are available.

    $IV_AUDIT_DETAIL_DELTA$

    Displays audit data if the audit details are available.



    Caution

    For syslog message to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each parameter. Example: $ATTACK_TIME$

  3. Click Save to save the customized syslog message.