The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward alert notifications from the Manager to a syslog server

Prev Next

Alerts forwarded from the Manager to a syslog server enable you to view the alerts on the third-party applications that support UDP and TCP over SSL, for example, Syslog NG.

  1. Select Manager → <Admin Domain Name> → Setup → Notification → IPS Events → Syslog.

    GUID-BB064D58-675D-4EFE-82BF-B30B6435A7E0-low.png
  2. Click Yes in Enable Syslog Notification to enable syslog forwarding of alerts.

  3. Click Save.

    Note

    You can forward Sensor alerts to multiple syslog servers by creating new syslog notification profiles. You can forward IPS alerts to syslog servers using UDP or TCP (with or without SSL).

  4. The columns displayed under the Syslog Notification Profiles section are as follows:

    Field

    Description

    Target Server Profile Name

    The profile name of the target server from where notifications are sent

    Facility

    The facility defined in the Edit a Syslog Notification Profile page

    Serverity Mappings

    The severity mappings defined in the Edit a Syslog Notification Profile page

    Notification Logic

    The logic by which the notifications are sent to the target server

    Message Preference

    The message preference you defined - Default or Custom