The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show auditlog

Prev Next

This command displays the system events in audit log based on user input. It displays the following information:

  • Date and time of the system event

  • User login details (login success/failure, user name, host IP and port number)

  • Name of the executed CLI commands (with parameters that are used)

Syntax:

show auditlog <[2-50] | all>

where [2-50] indicates the number of recent audit log events. This command should be executed with a parameter value, else the command is treated as invalid.

Sample Output:

intruShell@john> show auditlog all

Jan 28 09:51:49 2014:EXEC CMD : disable user - admin

Jan 28 09:52:22 2014:EXEC CMD : show auditlog all user - admin

Jan 28 09:52:35 2014:EXEC CMD : show auditlog 3 user - admin

Example:

To display the recent 20 events: show auditlog 20

To display all events: show auditlog all

Applicable to:

NS-series Sensors