The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable log forwarding in Secondary Manager

Prev Next

Users can enable log forwarding in the Secondary Manager within an MDR pair. This can be done by updating the value of iv.core.mdr.forwarding attribute in the ems.properties file within the Manager server. The possible values to be updated are ['A','F','L','C','N'] or [0], where:

A represents Alerts

F represents Faults

L represents Audit events

C represents Access Control Lists

N represents NTBA Quarantine events

0 is the default value set to the attribute, meaning log forwarding is disabled on the Secondary Manager

To edit the ems.properties file in the Manager, follow these steps:

Windows based Manager server

  1. RDP to the Manager server.

  2. In the ems.properties file, locate the following:

    iv.core.mdr.forwarding=0
  3. Go to <Manager_Install_Dir>\config\ems.properties

    Note

    The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

  4. To enable log forwarding, assign a value associated with the alerts you plan to forward. An example of enabling fault logs is shown below:

    iv.core.mdr.forwarding=F

    Note

    You can enable single or multiple log types based on your requirement. If you want to enable forwarding multiple log types, enter the values separated by |. For example, if you want to enable fault and audit logs, update the attribute as iv.core.mdr.forwarding=F|A.

    Note

    If you later plan to disable log forwarding, assign the value 0 or any other positive number to the attribute.

  5. Save the changes.

  6. Reboot the Manager server.

Linux based Manager server

  1. Log in to the Manager shell.

  2. Execute the edit ems.properties command.

    Note

    The edit command will edit the file using vi-editor. Trellix recommends you to use vi_editor command to perform editing operations on the files.

  3. In the ems.properties file, locate the following:

    iv.core.mdr.forwarding=0
  4. To enable log forwarding, assign a value associated with the alerts you plan to forward. An example of enabling fault logs is shown below:

    iv.core.mdr.forwarding=F

    Note

    You can enable single or multiple log types based on your requirement. If you want to enable forwarding multiple log types, enter the values separated by |. For example, if you want to enable fault and audit logs, update the attribute as iv.core.mdr.forwarding=F|A.

    Note

    If you later plan to disable log forwarding, assign the value 0 or any other positive number to the attribute.

  5. Save the changes.

  6. Execute the reboot command to restart the Manager server.