The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration for fault information

Prev Next

Fault provides information about the current status of your Trellix IPS installation. Fault notification can be configured based on the severity of a fault.

A complete list of faults is available in the %programfiles%\Trellix\IPS Manager\App\config\FaultNameAndText.properties file.

You can use the following methods to forward fault information:

  • SNMP traps
  • Syslog
  • Scripts
  • Email
  • Pager

If you are parsing fault notifications, it is recommended that you customize the notification that suits your needs.

Note

Default fault notification format may change in newer releases of the Manager.

The following table details the methods to forward fault information.

Method Information
SNMP traps You need the following to configure the Manager to send SNMP traps:
  • SNMP trap daemon to receive traps
  • SNMP trap server IP address
  • SNMP trap server Community string
  • SNMP trap server port

    Note

    If you are using SNMPv3, you might also need the following:

    • Authentication type
    • authentication password
    • Encryption type
    • Privacy password
Syslog You can configure the Manager to notify syslog servers for alerts, system faults, Firewall access rule matches, and user-activity audit for the Manager. If you enable syslog notification for Firewall access rules, and if you have enabled Firewall access rules logging per Sensor, the Manager sends a syslog message to the configured syslog server for each connection attempt matching an rule. This enables you to track your users' connection attempts and the results.

You need the following to configure the Manager to forward syslog messages:

  • Syslog server IP
  • Communication port number
  • Syslog facility

Note

Syslog is based on UDP. Therefore, the Manager doesn’t retransmit data in case of network connectivity issues or if the syslog server is unreachable.

Configuring syslog notification involves the following steps:

  1. To forward alerts to a syslog server, configure the syslog details in the Manager. See Trellix Intrusion Prevention System Product Guide.

  2. To forward fault notifications to a syslog server, configure the syslog details at Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog. See the Manager’s Help for the steps.

  3. To forward ACL rule matches to a syslog server, configure the syslog details in the Manager. See Trellix Intrusion Prevention System Product Guide
  4. To forward user-activity details of the Manager server to a syslog, configure the details at Manager → <Admin Domain Name> → Setup → Notification → User Activity → Syslog. See the Manager’s Help for the steps.
Email and pager You can configure the Manager to do the following:
  • Notify alerts and faults through email or pager.
  • Send scheduled reports through email.

Note the following:

  • Make sure the antivirus application is not blocking outgoing emails.
  • Make sure you have enabled mail relay on the SMTP server.

Configuring email notification involves the following steps:

  1. Configure the email server settings in the Manager. The following features use this email server settings:
    • Reports
    • Fault notification
    • Alert notification
    • Pager

    See the Trellix Intrusion Prevention System Product Guide for the details.

  2. To enable e-mail notification only for specific attacks, edit those attacks in the relevant policies. See Trellix Intrusion Prevention System Product Guide
  3. For alert notification through email or pager, configure the email notification and the email recipients in the Manager. See Trellix Intrusion Prevention System Product Guide.
  4. To enable fault notification through email or pager, configure the email notification and the email recipients in the Manager. Go to Manager → <Admin Domain Name> → Setup → Notification → Faults → E-mail. See the Manager’s Help for the steps.
  5. To enable the Manager to email auto-generated reports, configure the recipients in the General Settings of the Reports module. See Trellix Intrusion Prevention System Product Guide
Scripts Scripts are useful for complex integrations. Scripts are a sequence of commands that can use template variables. The Manager replaces these variables with the relevant values before executing the command. For example, you can use scripts to extract information from the alerts and send customized emails for specific conditions.

Scripts can invoke another batch file and provide variables as command line parameters for the invoked program. For more information, refer to Trellix Intrusion Prevention System Product Guide. Also see the Readme.doc at %programfiles%\Trellix\IPS Manager\App\diag\AlertNotificationScript

Suppression While configuring some of the notification methods, you can specify the suppression time value. Suppression time is the time (minutes and seconds) the Manager should wait after an alert notification has been sent before sending another alert notification. The default and minimum value is 10 minutes. Suppression time is useful to avoid sending excessive notifications when there is heavy attack traffic.

The specify suppression time value for the following notification methods:

  • Email
  • Pager
  • Scripts

Suppression time value does not apply to syslog and SNMP. All events are forwarded.