The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize the syslog forwarder message

Prev Next

Prerequisite: You must have saved the syslog server details successfully in the Syslog page.

Steps:

  1. To access the Syslog page from the Manager tab, do the following.

    1. Click the Manager tab.

    2. From the Domain drop-down list, select the domain you want to work in.

    3. Select Setup → Notification → IPS Quarantine Access Events.

      Option

      Definition

      Enable Syslog Logging?

      Select Yes to enable syslog and No to disable syslog.

      Applicable Admin Domains

      Current — Refers the admin domain currently selected. This is enabled by default.

      Children — Refers the child admin domains of the current domain.

      Target Syslog Server Name or IP Address

      The IP address or name of the syslog server which becomes the destination of the alert notifications sent by all devices.

      Note

      The length of server name has been increased to support up to 255 characters from 40 characters.

      Target Syslog Server UDP Port

      Port on the target syslog server that is authorized to receive syslog messages.

      The default protocol for syslog forwarding from Sensors is UDP. Therefore, this port must not be altered.

      Syslog Facility

      Standard syslog prioritization value. The choices are as follows:

      • Security/authorization (code 4)

      • Security/authorization (code 10)

      • Log audit (note 1)

      • Log alert (note 1)

      • Clock daemon (note 2)

      • Local user 0 (local0)

      • Local user 1 (local1)

      • Local user 2 (local2)

      • Local user 3 (local3)

      • Local user 4 (local4)

      • Local user 5 (local5)

      • Local user 6 (local6)

      • Local user 7 (local7)

      Syslog Priority

      You can map each severity (Informational, Low, Medium, or High) to one of these standard syslog severities:

      • Emergency – System is unusable

      • Alert – Action must be taken immediately

      • Critical – Critical conditions

      • Error – Error conditions

      • Warning – Warning conditions

      • Notice – Normal but significant condition

      • Informational – Informational messages

      • Debug – Debug-level messages

      Message Body

      System default — The default message is a quick summary of an event.

      Customized — Personalized message of an event.

      Important

      Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

      As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

  2. Click Test Connection in the page.

  3. Click Edit in the Message Body field in the page.

    The Customize Syslog Forwarder Message page displays.

  4. Customize the format for the syslog forwarder message.

    Option

    Definition

    Message

    Form the message by typing in the required text and by clicking on the parameters provided below this field.

    Important

    For Syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $SENSOR_NAME$

    Save

    Saves the message you created. Displays the IPS Quarantine Access Events page when you click.

    Cancel

    Cancels the changes you made to the message.

    Reset to System Default

    After you customize the syslog message, the Reset to System Default button appears in the Customize Syslog Forwarder Message page. Click this button to revert to the system default message.

  5. Click Save.