The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward faults to a Syslog server

Prev Next

The Manager → Setup → Notification → Faults → Syslog option enables the forwarding of Trellix IPS faults to a syslog server. Syslog forwarding enables you to view the forwarded faults via a third-party syslog application. For syslog forwarding, the root domain and parent domains have the option to include faults from all corresponding child domains.

Following are the Syslog variables for fault notification:

Syslog variables for fault notification

Syslog variable name

Description

$IV_ACK_INFORMATION$

Displays additional acknowledgment information when a created fault is acknowledged after the hysteresis period.

$IV_ADDITIONAL_TEXT$

Displays additional text for the raised fault.

$IV_ADMIN_DOMAIN$

Name of the domain.

$IV_DESCRIPTION$

Description of the fault.

$IV_DEVICE_NAME$

Name of the device.

From the 11.1 Update 9 release, it also displays the hostname and IP addresses of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

$IV_FAULT_COMPONENT$

The component for which the fault is generated.

$IV_FAULT_LEVEL$

Displays the fault level (Manager system level, Sensor level, or Sensor interface level)

$IV_FAULT_NAME$

The name of the fault.

$IV_FAULT_SOURCE$

Indicates if the fault is generated by the Manager or sent by the Sensor.

$IV_FAULT_TIME$

The time at which the fault is generated.

$IV_FAULT_TYPE$

Indicates if the event is created, acknowledged, or cleared.

$IV_OWNER_ID$

ID of the Manager or the Sensor.

$IV_RECOMMENDED_ACTION$

The next steps recommended for the fault.

$IV_SEVERITY$

The severity of the fault (critical, error, or warning).