The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting up rsyslog servers

Prev Next

To set up rsyslog servers, perform the following subtasks:

  • Add the rsyslog servers

  • Configure the rsyslog servers

To add an rsyslog server:
  1. Enable the CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable rsyslog notifications:

    hostname (config) # fenotify rsyslog enable

  3. Specify the name of the rsyslog server (for example, AX5400) to receive the notification:

    hostname (config) # fenotify rsyslog trap-sink sink_name

  4. Specify which servers will receive rsyslog notifications (one server per command):

    hostname (config) # fenotify rsyslog trap-sink sink_name enable

  5. Specify the IP address or DNS address of the rsyslog server to send event logs to:

    hostname (config) # fenotify rsyslog trap-sink sink_name address ip address

  6. Save the configuration:

    hostname (config) # write memory

To configure the rsyslog servers:
  1. Enable the CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable rsyslog notifications:

    hostname (config) # fenotify rsyslog enable

  3. Specify that an rsyslog notification is sent each time a malware object is detected:

    hostname (config) # fenotify rsyslog trap-sink sink_name prefer message delivery per-event

  4. Specify the format for rsyslog notifications:

    Note

    The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.

    • To send notifications in the Common Export Format (CEF), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format cef

    • To send notifications in the comma-separated values (CSV) format, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format csv

    • To send notifications in the Log Extended Event Format (LEEF) (default), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format leef

    • To send notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-concise

    • To send notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-extended

    • To send notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format xml-normal

    • To send notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-concise

    • To send notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-extended

    • To send notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format json-normal

    • To send notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-concise

    • To send notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-extended

    • To send notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message format text-normal

  5. Specify the severity classification for the rsyslog notification:

    Note

    Trellix recommends setting the severity classification to alert.

    • To indicate that action must be taken immediately (severity 1), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as alert

    • To indicate that the notification contains critical conditions (severity 2), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as crit

    • To indicate that the notification contains debug-level messages (severity 7), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as debug

    • To indicate an emergency (the system is unusable) (severity 0), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as emerg

    • To indicate that the notification contains error conditions (severity 3), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as error

    • To indicate that the notification contains informational messages (severity 6), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as info

    • To indicate normal but significant conditions (severity 5), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as notice

    • To indicate that the notification contains warning conditions (severity 4), enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name prefer message send-as warning

  6. Specify the protocol used to send rsyslog notifications (UDP is the default):

    • To select UDP, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name protocol UDP

    • To select TCP, enter:

      hostname (config) # fenotify rsyslog trap-sink sink_name protocol TCP

  7. Save the configuration:

    hostname (config) # write memory