The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

sshlogupload

Prev Next

Use this command to upload the SSH log file to the SCP Server.

Ensure the following before using this command:

  • The SCP server IP address must be set using the command set scpserver ip <server_ip>.

The file uploaded on the SCP server is the TAR file containing one or more zipped files:

  • Untar the file using the command tar –xvf <filename> to get the individual zipped files.
  • Each file must be unzipped using the command gunzip <zipped_file> to view the file.
  • For NS-series Sensors, when loading the SSH log file to the SCP server, the first attempt will be based on SSH public key authentication. If that fails, the Sensor will fall back to the password authentication. If SSH public key authentication is successful, you will not be prompted for the SCP server credentials.

Syntax

sshlogupload scp word

A sample SSH log message is displayed below:

Sep 16 09:09:52 localhost kernel: SSHD_DROP:IN=eth0 OUT= 
MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 SRC=172.16.232.47 
DST=172.16.199.89 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=4286 DF 
PROTO=TCP SPT=2821 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0

Note

SSH log only contains entries for SSH accept or SSH drop from a particular client IP address as defined in the ACL.

Log Message Fields Description
SSHD_DROP The Log prefix. It can be SSHD_DROP or SSHD_ACCEPT.
IN=etho Interface the packet was received from; empty value for locally generated packets
OUT= Interface the packet was sent to; empty value for locally received packets
MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00

The MAC field consisting of 14 entities, separated by colons, and this can read as:

  • Dest MAC= 00:06:92:25:9d:80 - The destination MAC address
  • Src MAC=00:0b:bf:a1:b7:fc - The source MAC address
  • Type=08:00 - Ethernet frame carrying an IPv4 datagram
SRC=172.16.232.47

DST=172.16.199.89

Source IP address

Destination IP address

LEN=48 The total length of IP packet in bytes
TOS=0x00

PREC=0x00

The Type Of Service, “Type” field

The Type Of Service, “Precedence” field

TTL=127 The remaining Time To Live is 127 hops.
ID=4286

DF

The unique ID for this IP datagram, shared by all fragments if fragmented

Do not Fragment flag

PROTO=TCP The protocol name
SPT=2821

DPT=22

WINDOW=65535

The source port

The destination port

The number of bits specified on the “Window Scale” TCP option

RES=0x00 The reserved bits
SYN

URGP=0

The synchronize flag which is only exchanged at TCP connection establishment

The urgent flag

Applicable to:

NS-series Sensors