The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to view the details of matched traffic

Prev Next

For all traffic that matched an Access Rule, the Sensor can forward the details to a syslog server. You can use these details for analysis and reporting purposes. For example, you can view all the hosts that tried to access social networking sites during a specific time period. You can also log the packets that matched your Firewall Access Rules.

To view the details of matched traffic you need to configure the following:

  • Configure a syslog server and ensure that it is accessible to the Sensor’s Management port if you want the Sensor to send the logged details directly to the syslog server. Alternatively, if you want the Sensor to send the details through the Manager, then the Manager must be able to communicate to the syslog server. In this case, the Sensor forwards the logs to the Manager, which formats and converts them to syslog messages and sends them to the configured syslog server.

    Note

    Only NS-series Sensors can directly send logs to a syslog server.

    You can then view the log from a third-party Syslog application.

    Note

    For syslog forwarding, the admin domains have the option to include the logs from the corresponding child domains.

  • Enable Firewall Rule Match Notification at the admin domain level.

  • Enable Firewall Logging at the Sensor level.