The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling SSL session logging using the CLI

Prev Next

Use the CLI commands in this section to enable or disable the Network Security appliance to collect statistics about traffic from the SSL flows.

Note

You can enable or disable SSL session logging only using the CLI.

Prerequisites

To enable the collection of SSL flow statistics:

The "Status" line displays "enabled" to indicate that the SSL session log module can generate logs on the Network Security appliance. The "Listening State" line displays "Ready" to indicate that the SSL session log mechanism is ready to process requests.

  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable the collection of statistics.

    hostname (config) # session-logger enable
  3. Verify that the module is ready to collect statistics.

    hostname (config) # show session-logger statusStatus : enabled
    Listening State: Ready
    
    Module Name     : Status
    ------------------------
    ssl             : OFF
To disable the collection of SSL flow statistics:
hostname (config) # show session-logger status
Status : disabled
Listening State: Ready(but admin disabled)

The "Status" line displays "disabled" to indicate that the SSL session log process cannot generate logs on the Network Security appliance. The "Listening State" line displays "Ready (but admin disabled)" to indicate that the SSL session log mechanism has been stopped by the administrator.

  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable the collection of statistics.

    hostname (config) # no session-logger enable
  3. Verify that the module is not collecting statistics.