The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Log UI redesign

Prev Next

Previously, logs related to the Manager and the Sensor were available across multiple pages like System Log, System Faults, Running Tasks, User Activity Log, and MDR Failover Log in the Manager.

With this release of 10.1, the Logs page is introduced to consolidate several types of logs pages and enhance the user experience in accessing the logs.

The Logs page has 5 individual tabs called Faults, System Events, Background Tasks, User Activities, and MDR Events.

The tabs in the Logs page provide detailed information regarding any individual log inline, and does not navigate to a new page for detailed view like previous versions.

The following table lists the previous names and the new names for the log types:

In 9.2 Manager In 10.1 Manager
System Faults Faults
System Log System Events
Running Tasks Background Tasks
User Activity Log User Activities
MDR Failover Log MDR Events

Filter logs

You can filter logs based on the period in which the logs were generated. The Custom Time Period option lets you customize the time period. When the time period option is selected, the logs are displayed for the chosen time period. By default, the logs for the last 7 days are displayed.

When looking for a particular log, you can enter the keyword for the log in the Quick Search field and the results are automatically displayed in the log. Click Clear All Filters to undo all filters applied. The button color and the column header color changes to orange which indicates that a filter is active and that the particular logs tab is not displaying all entries.

The entries in different tabs of the Logs page are not refreshed automatically. Use the refresh icon to view new logs generated. Use the arrow keys at the bottom of the page to navigate back and forth between the pages in a tab.

Sort/Group logs

The tabs in the Logs page display thousands of log items and it consumes time to search for a specific type of log item. To find a particular log item, the grouping feature is available in the Logs page. Using this feature, you can sort or group the logs based on specific fields, and view a consolidated list of logs.

Different sorting options available in each column are as follows:

Options Definition
Sort Ascending

Sorts the logs table in ascending order with the column header as core attribute

Sort Descending

Sorts the logs table in descending order with the column header as core attribute

Columns

Allows you to select the columns to be displayed on a particular tab

Group by this field Allows you to group log table entries on the particular fields in a column

Note

The options in the Group by this field vary across the columns on a tab.

Filters Allows you to apply filters to specific columns on a tab

Note

The options in the Filters vary across the columns on a tab.

You can view the Logs page at Manager → <Admin Domain Name> → Troubleshooting → Logs.

Faults

The Faults tab page displays messages that are generated to detail the system faults experienced by Trellix IPS.

To view the faults, go to Manager → <Admin Domain Name> → Troubleshooting → Logs and select Faults tab to view the system faults.

System Events

The System Files tab enables a privileged user to view system information either by user activity or general system information. The System Files tab pulls user-activity information from the database and system-activity information from the log files (such as ems.log files), thus providing a beneficial resource for analysis and/or problem-solving.

To view the faults, go to Manager → <Admin Domain Name> → Troubleshooting → Logs and select System Events tab to view the system information.

Background Tasks

The Running Tasks monitor of the Dashboard page displays the status of currently in-progress activities on your system that the Trellix IPS identifies as long running processes.

When a long running process is taking place in your Manager, the status is displayed as In progress in the Running Tasks monitor. You can also go to the Logs page and select Background Tasks tab to view long running processes. Once the activity is completed, the entry for that activity is removed from the Running Tasks monitor and displayed only under the Background Tasks tab in the Logs page.

To view the faults, go to Manager → <Admin Domain Name> → Troubleshooting → Logs and select Background Tasks tab to view long running processes.

User Activities

The User Activities tab enables the administrator to view all user actions in the management system. An audit can help to determine what a user has done to determine mistakes, overwriting, or other issues about user activity.

To view the faults, go to Manager → <Admin Domain Name> → Troubleshooting → Logs and select User Activities tab to view all user action.

MDR Events

The MDR Events tab enables you to view previous MDR activities, including the date and time on which the activity occurred, the users performing the activity, and the nature of the activity.

To view the faults, go to Manager → <Admin Domain Name> → Troubleshooting → Logs and select MDR Events tab to view previous MDR activities.