The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward audit information to Syslog Server

Prev Next

The User Activity option enables the forwarding of Trellix IPS audit information to a syslog server. Syslog forwarding enables you to view the forwarded audit information via a third-party syslog application. For syslog forwarding, the root domain and parent domains have the option to include audit information from all corresponding child domains. To enable syslog forwarding for audit notification, do the following:

  1. Select Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog.

    The Syslog page is displayed.

    GUID-6B976454-D2F7-4ADC-9BEE-F6EDFEDD8067-low.png
  2. Fill in the following fields:

    Field

    Description

    Enable Syslog Notification

    Yes is enabled; No is disabled

    Admin Domain

    • Current— Send notifications for audit information in the current domain. Always enabled for current domain.

    • Children— Include audit information for all child domains of the current domain.

    Target Server

    Choose the target server from the drop-down to which audit information is forwarded.

    Facilities

    Standard syslog prioritization value. The choices are as follows:

    • Security/authorization (code 4)

    • Security/authorization (code 10)

    • Log audit (note 1)

    • Log alert (note 1)

    • Clock daemon (note 2)

    • Local user 0 (local0)

    • Local user 1 (local1)

    • Local user 2 (local2)

    • Local user 3 (local3)

    • Local user 4 (local4)

    • Local user 5 (local5)

    • Local user 6 (local6)

    • Local user 7 (local7)

    Result Mapping

    You can map each audit result (Failed to, Successful to, and In Progress to) to one of the standard syslog severities listed below (default result severities are noted in parentheses):

    • Emergency— System is unusable

    • Alert— Action must be taken immediately

    • Critical— (HIGH) Critical conditions

    • Error— Error conditions

    • Warning— (MEDIUM) Warning conditions

    • Notice— (LOW) Normal but significant condition

    • Informational— (INFORMATIONAL) Informational message

    • Debug— Debug-level messages

    Forward Audit

    Select the severity of the audit that you want to be forwarded to the syslog server. The options are:

    • Allow all Auditlogs

    • Failed only

    • Successful only

    • In Progress only

    Message Preference

    Select the preference of the message. The options are:

    • System default— This is available by default

    • Customized— This is available once the notification is enabled

  3. Click Apply.

    Note

    You must click Apply before you will be able to customize the message format sent to your syslog server.

  4. Select the Message Preference to send as the syslog forwarding message. The choices are:

    • System Default — The default message is a quick summary of a fault with three fields for easy recognition: Action, Result, and Time. A default message reads:

      $IV_AUDIT_ACTION$ $IV_AUDIT_RESULT$ at $IV_AUDIT_TIME$
    • Customized — Create a custom message. To create a custom message, do the following:

      1. Click Edit to create a custom message.

      2. Type a message and select (click) the parameters for the desired alert identification format. The following figure displays a custom message. You can type custom text in the Message field as well as click one or more of the provided elements below the field box.

      3. Click Save when finished to return to the Syslog page. The Customized button is automatically selected after you have customized the Message Preference.

        A few important points to consider:

        • For syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $ATTACK_TIME$

        • From 11.1 Update 9 release, $IV_MANAGER_DETAILS$ is introduced to display the hostname and IP addresses of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

        • From the 11.1 Minor 6 release, the IPS Manager can send 16384 bytes in a single syslog message.

        • Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

          As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

        Syslog variables for audit notification

        Syslog variable name

        Description

        $IV_AUDIT_ACTION$

        The audit action value based on the action ID that was passed.

        $IV_AUDIT_RESULT$

        Indicates the stage of auditing (received, succeeded, failed, or ongoing).

        $IV_AUDIT_TIME$

        Time stamp of the audit message.

        $IV_AUDIT_MESSAGE$

        The audit message.

        $IV_AUDIT_USER$

        The username for the audit.

        $IV_AUDIT_CATEGORY$

        The action taken for the audit.

        $IV_AUDIT_DOMAIN$

        Name of the domain.

        $IV_AUDIT_DETAIL_COMMENT$

        Displays committed comments if the audit details are available.

        $IV_AUDIT_DETAIL_DELTA$

        Displays audit data if the audit details are available.

        $IV_MANAGER_DETAILS$

        The hostname and IP address of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.



  5. Click Save.