The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward faults to a Syslog server

Prev Next

The Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog option enables the forwarding of Trellix IPS faults to a syslog server. Syslog forwarding enables you to view the forwarded faults via a third-party syslog application. For syslog forwarding, the root domain and parent domains have the option to include faults from all corresponding child domains.

To enable syslog forwarding for fault notification, do the following:

  1. Select Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog (same for Central Manager).

    The Syslog window is displayed.

    GUID-1F7EB9BA-76C0-4D82-9A70-BEF356CCD8ED-low.png
  2. Configure the following fields:

    Field

    Description

    Enable Syslog Notification

    Yes is enabled; No is disabled

    Admin Domain

    Select the below options to enable admin domain notification:

    • Current— Send notifications for alerts in the current domain. Always enabled for current domain.

    • Children— Include alerts for all child domains of the current domain.

    Note

    This field is not present for Central Manager.

    Target Server

    Choose the target server from the drop-down to which faults are forwarded.

    Facilities

    Standard syslog prioritization value. The choices are as follows:

    • Security/authorization (code 4)

    • Security/authorization (code 10)

    • Log audit (note 1)

    • Log alert (note 1)

    • Clock daemon (note 2)

    • Local user 0 (local0)

    • Local user 1 (local1)

    • Local user 2 (local2)

    • Local user 3 (local3)

    • Local user 4 (local4)

    • Local user 5 (local5)

    • Local user 6 (local6)

    • Local user 7 (local7)

    Severity Mapping

    You can map each fault severity (Informational, Error, Warning, and Critical) to one of the standard syslog severities listed below (default severity mappings are noted in parentheses):

    • Emergency— System is unusable

    • Alert— Action must be taken immediately

    • Critical— (HIGH) Critical conditions

    • Error— Error conditions

    • Warning— (MEDIUM) Warning conditions

    • Notice— (LOW) Normal but significant condition

    • Informational— (INFORMATIONAL) Informational messages

    • Debug: Debug-level messages

    Forward Faults

    Select the severity of the faults that you want to be forwarded to the syslog server. The options are:

    • Critical— Only Critical faults

    • Error and above— Both Error and Critical faults

    • Warning and above— Warning, Error, and Critical faults

    • Informational and above— All faults

  3. Click Save.

    Note

    You must click Save before you will be able to customize the message format sent to your syslog server.

  4. Select the Message Preference to send as the syslog forwarding message. The choices are:

    • System Default — The default message is a quick summary of a fault with two fields for easy recognition: Device Name and Description. A default message reads:

      Fault : $IV_DEVICE_NAME$: $IV_DESCRIPTION$ 
    • Customized — Create a custom message. To create a custom message, do the following:

      1. Click Edit to create a custom message.

      2. Type a message and select (click) the parameters for the desired alert identification format. The following figure displays a custom message. You can type custom text in the Message field as well as click one or more of the provided elements below the field box.

      3. Click Save when finished to return to the Syslog page. The Customized button is automatically selected after you have customized the Message Preference.

        A few important points to consider:

        • For syslog information to appear correctly, ensure that you use the dollar-sign ($) delimiter immediately before and after each element. Example: $ATTACK_TIME$

        • From the 11.1 Update 9 release, $IV_DEVICE_NAME$ will also display the hostname and IP addresses of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

        • From the 11.1 Minor 6 release, the IPS Manager can send 16384 bytes in a single syslog message.

        • Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.

          As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.

        Syslog variables for fault notification

        Syslog variable name

        Description

        $IV_ACK_INFORMATION$

        Displays additional acknowledgment information when a created fault is acknowledged after the hysteresis period.

        $IV_ADDITIONAL_TEXT$

        Displays additional text for the raised fault.

        $IV_ADMIN_DOMAIN$

        Name of the domain.

        $IV_DESCRIPTION$

        Description of the fault.

        $IV_DEVICE_NAME$

        Name of the device; hostname, and IP addresses of the Manager. For an MDR setup, it further specifies if the Manager is primary or secondary.

        $IV_FAULT_COMPONENT$

        The component for which the fault is generated.

        $IV_FAULT_LEVEL$

        Displays the fault level (Manager system level, Sensor level, or Sensor interface level)

        $IV_FAULT_NAME$

        The name of the fault.

        $IV_FAULT_SOURCE$

        Indicates if the fault is generated by the Manager or sent by the Sensor.

        $IV_FAULT_TIME$

        The time at which the fault is generated.

        $IV_FAULT_TYPE$

        Indicates if the event is created, acknowledged, or cleared.

        $IV_MEMBER_DEVICE_NAME$

        Name of the Sensor.

        $IV_OWNER_ID$

        ID of the Manager or the Sensor.

        $IV_SEVERITY$

        The severity of the fault (critical, error, or warning).



  5. Click Save.