The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable rule match notification

Prev Next
  1. Click the Manager tab.

  2. From the Domain drop-down list, select the domain you want to work in.

  3. Select Setup → Notification → Firewall Access Events.

  4. Specify the domain-level syslog details in the corresponding fields.

    Syslog server details for Firewall Access Events
    Syslog server details for Firewall Access Events


    Option

    Definition

    Enable Syslog Notification

    If you select Yes, the details of the traffic that matched an access rule is forwarded to a syslog server. You can also configure the details now and enable it at a later time.

    Admin Domains

    • Current — The syslog configuration applies only to the current domain. This is always enabled for the current domain.

    • Children — The syslog configuration applies to child domains as well. You can also modify this syslog configuration at a child domain if required.

    Server Name or IP Address

    Enter the syslog server name or its IP (IPv4 or IPv6) address. If you specify the syslog server name:

    • The Manager uses the DNS servers configured in its TCP/IP properties.

    • If you choose the Sensor to forward the logs to a syslog, then the Sensor uses the DNS servers that you configured in the Name Resolution page for the Sensor.

    Note

    The length of server name has been increased to support up to 255 characters from 40 characters.

    Port

    Enter the communication port number on the target server which is authorized to receive syslog messages. The standard port for syslog, which is 514, is pre-filled in the field. If you are using a non-standard port, then replace 514 with that number.

    Facility

    Lists the syslog prioritization values.

    By default, the syslog messages forwarded to a syslog server are of Security authorization prioritization value.

    Severity

    Lists the syslog priority values.

    By default, the syslog messages forwarded to a syslog server are of Debug severity.

    Message Body

    Optionally, customize the default syslog message. There are two types:

    • System Default — The default message is a quick summary for easy recognition. A default message reads (visible in the Message field of the Customize Syslog Forwarder Message page):

      "$IV_SENSOR_NAME$$IV_ACL_ID$$IV_ACL_ACTION$$IV_APPLICATION_PROTOCOL$$IV_SOURCE_IP$$IV_SOURCE_PORT$ $IV_DESTINATION_IP$$IV_DESTINATION_PORT$"

    • Customized — You can customize the message after you successfully save the syslog configuration details. Click Test Connection to view the option to edit the default message.

    Important

    Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

    As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

    Test Connection

    Checks if the Manager is able to send logs to the syslog server. Check your syslog server if it has received the test message from the Manager. If not, check the syslog server name or IP address that you had provided. Ping the syslog server from the Manager server to see if the Manager is able to reach the syslog server. If you plan to configure NS-series Sensors to directly send the messages to the syslog server, ping the syslog server from the Sensor's CLI. This option is available in the Firewall Logging page.

    Note

    You can use the test connection feature, even if you have set Enable Syslog Forwarding? to no.

    Save

    Saves the syslog configuration changes in the Manager database. Once you click Save, you will be able to customize the message format sent to the syslog server.

    Note

    If you have modified the syslog configuration, then do a configuration update of the Sensors for the changed settings to take effect.

  5. Click Save.

    Note

    Once you click Save, you will be able to customize the message format sent to the syslog server.

  6. Do a Configuration Update for the Sensors for the notification settings to take effect.

    Note

    Use the show acl stats command in the Sensor's CLI to see the count of ACL logs sent through the Manager.