The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How the Sensor receives user details

Prev Next
  1. The Manager sends user-data updates to Sensors when both of these conditions are met:

    • NS-series Sensors of software version 10.1 or above

    • At least one of the Sensor's resources has been assigned a user-based Firewall access rule or QoS rule.

  2. The updates to the Sensors includes the following information:

    • IP to user mapping

    • User to user group mapping

    • List of user groups

  3. Manager sends the updates using TFTP (standard ports). It sends the updates to both the member Sensors in case of failover.

  4. The Manager updates the Sensor in two ways:

    • Full update — that is the Manager sends the entire set of user-data that it currently has to the relevant Sensors. This update entirely refreshes the user-data on a Sensor.

    • Incremental update every one minute — the Manager sends just the changes since the last update.

  5. If you have an MDR, only the active Manager sends the updates to the Sensors. If you have a HA pair of Sensors, the active Manager sends the updates to both the Sensors. Whenever the active Manager goes down, the standby Manager sends a full update to the Sensors as soon as it becomes the active Manager.

  6. The Manager sends the full update under the following conditions:

    • Sensor reboot

    • If the communication channel between the Manager and Sensor that is used for the updates comes up again

    • Manager restarts

    • By default, at 1200 hours everyday; this is not user-configurable

    • When a standby Manager in an MDR pair becomes the active Manager

    • When connection between the Manager and Trellix Logon Collector is re-established

    Note

    The Manager re-sends an update until it succeeds.

Deriving user details using Kerberos traffic: If the Manager-Trellix Logon Collector communication is disrupted for some reason, the user information with the Sensor might not be current. As a redundant measure, the Sensor is designed to passively snoop Kerberos traffic passing through its monitoring ports. This typically happens when users attempt to log on using their AD credentials. The Sensor sends the user details from the snooped Kerberos traffic to the Manager. Then the Manager communicates with the AD servers to validate the user credentials. This Kerberos-based detection of user details is independent of the updates from Trellix Logon Collector. The updates from Trellix Logon Collector and the user details through Kerberos are used to update the same set of data. When you create user-based rules, only the user names and user groups received through updates from Trellix Logon Collector are displayed. The user names derived through Kerberos snooping are not displayed.

Note

In case of Sensor failover, the Sensor that detected the Kerberos traffic sends the details to the Manager. It also sends the details to its peer Sensor. The peer Sensor sends the same details to the Manager. The Manager verifies with the AD servers and responds to both the Sensors separately. In case of MDR pair, the process is same but only the active Manager is involved.