The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager data available for SIEM products

Prev Next

There are various methods by which you can extend Manager data to SIEM products. You can choose one based on the data involved and the type of the SIEM product.

The following methods are available:

  • Configure the Manager to push data to a SIEM product.
  • Configure a SIEM product to pull data from the Manager.
  • Query the Manager database for data.

The Manager itself provides multiple methods for backing up configuration and analysis data, including all policy, ignore rule, alert, and any associated packet information. These backup, archive, and export techniques, however, will only allow for the retrieval of the information through the Manager. A SIEM product must access the Manager through the standard system integration techniques.

The following data is available to SIEM products:

  • Alert information — When an attack is detected, an alert is raised and the configured response is executed. The alert information contains, where applicable, the specific attack details such as type, attacker and target addresses and ports, packet logs, and outcome.
  • Packet log information — A policy can include the requirement to log the packet information that is associated with an alert. This information is a record of the actual flow of traffic that triggered the attack and can be used for detailed packet analysis. This information must be pulled from the Manager database.
  • System Faults — Fault information contains the following details:
    • Admin domain where the fault is detected
    • Sensor name
    • Name of the fault
    • Type of fault
    • Fault owner
    • Fault level
    • Time of the fault
    • Fault source
    • Fault component
    • Severity
    • Description
    • Acknowledged flag

    To view the list of all fault informational items, select Manager → <Admin Domain Name> → Setup → Notification → Faults → Syslog. Provide all the details and click Save. Then select Customized and click Edit. You can query faults from the iv_alarm table in the Manager database.

  • ACL Logs – Access Control Lists