The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Log monitoring

Prev Next

The NDR Series appliance includes commands to monitor the system. You can monitor NDR-specific logs and manage processes in KLISH. Shell access is not required to access logs.

The following logs are available:

Log Name

Description

auth

Displays an auth log of the system.

system

Displays a system log (npulse.log).

message

Displays logs from /var/log/messages.

elasticsearch

Displays an elasticsearch log for all the elastic nodes.

nginx

Displays logs for access and error from /var/log/ngingx.

audit

Displays audit logs from /var/log/audit.

Accessing logs

To access the NDR Series appliance logs:

Streaming logs and viewing historic logs

The following commands are available to stream and view historic logs:

Command

Description

continuous

Streams the selected log.

history

Displays all historic logs stored on the NDR for the selected log.

To continuously stream a log:

To view a historic log: