The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward faults to a Syslog server

Prev Next
The Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog option enables the forwarding of Trellix IPS faults to a syslog server. Syslog forwarding enables you to view the forwarded faults via a third-party syslog application. For syslog forwarding, the root domain and parent domains have the option to include faults from all corresponding child domains.

To enable syslog forwarding for fault notification, do the following:

Task

  1. Select Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog (same for Central Manager).
    The Syslog window is displayed.
  2. Fill in the following fields:
    Field Description
    Enable Syslog Notification Yes is enabled; No is disabled
    Admin Domain Select the below options to enable admin domain notification:
    • Current— Send notifications for alerts in the current domain. Always enabled for current domain.
    • Children— Include alerts for all child domains of the current domain.

    Note

    This field is not present for Central Manager.

    Server Name or IP Address Type either the Host IP Address or Host Name of the syslog server where alerts will be sent.

    For Host IP address, you can enter either IPv4 or IPv6 address.

    Note

    The length of server name has been increased to support up to 255 characters from 40 characters.

    Port Port on the target server which is authorized to receive syslog messages. The standard port for syslog, 514, is pre-filled in the field.
    Facilities Standard syslog prioritization value. The choices are as follows:
    • Security/authorization (code 4)
    • Security/authorization (code 10)
    • Log audit (note 1)
    • Log alert (note 1)
    • Clock daemon (note 2)
    • Local user 0 (local0)
    • Local user 1 (local1)
    • Local user 2 (local2)
    • Local user 3 (local3)
    • Local user 4 (local4)
    • Local user 5 (local5)
    • Local user 6 (local6)
    • Local user 7 (local7)
    Severity Mapping You can map each fault severity (Informational, Error, Warning, and Critical) to one of the standard syslog severities listed below (default severity mappings are noted in parentheses):
    • Emergency— System is unusable
    • Alert— Action must be taken immediately
    • Critical— (HIGH) Critical conditions
    • Error— Error conditions
    • Warning— (MEDIUM) Warning conditions
    • Notice— (LOW) Normal but significant condition
    • Informational— (INFORMATIONAL) Informational messages
    • Debug: Debug-level messages
    Forward Faults Select the severity of the faults that you want to be forwarded to the syslog server. The options are:
    • Critical— Only Critical faults
    • Error and above— Both Error and Critical faults
    • Warning and above— Warning, Error, and Critical faults
    • Informational and above— All faults
  3. Click Save.

    Note

    You must click Save before you will be able to customize the message format sent to your syslog server.

  4. Select the Message Preference to send as the syslog forwarding message. The choices are:
    • System Default— The default message is a quick summary of a fault with two fields for easy recognition: Attack Name and Attack Severity. A default message reads:
      Attack $IV_ATTACK_NAME$ ($IV_ATTACK_SEVERITY$)
    • Customized— Create a custom message. To create a custom message, do the following:
      1. Click Edit to create a custom message.
      2. Type a message and select (click) the parameters for the desired alert identification format. The following figure displays a custom message. You can type custom text in the Message field as well as click one or more of the provided elements below the field box.
      3. Click Save when finished to return to the Syslog page. The Customized button is automatically selected after you have customized the Message Preference.

        Caution

        For syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $ATTACK_TIME$

        Syslog variables for fault notification
        Syslog variable name Description
        $IV_ACK_INFORMATION$ Displays additional acknowledgment information when a created fault is acknowledged after the hysteresis period.
        $IV_ADDITIONAL_TEXT$ Displays additional text for the raised fault.
        $IV_ADMIN_DOMAIN$ Name of the domain.
        $IV_DESCRIPTION$ Description of the fault.
        $IV_DEVICE_NAME$ Name of the device.
        $IV_FAULT_COMPONENT$ The component for which the fault is generated.
        $IV_FAULT_LEVEL$ Displays the fault level (Manager system level, Sensor level, or Sensor interface level)
        $IV_FAULT_NAME$ The name of the fault.
        $IV_FAULT_SOURCE$ Indicates if the fault is generated by the Manager or sent by the Sensor.
        $IV_FAULT_TIME$ The time at which the fault is generated.
        $IV_FAULT_TYPE$ Indicates if the event is created, acknowledged, or cleared.
        $IV_MEMBER_DEVICE_NAME$ Name of the Sensor.
        $IV_OWNER_ID$ ID of the Manager or the Sensor.
        $IV_SEVERITY$ The severity of the fault (critical, error, or warning).
  5. Click Save.