The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

sshlogupload WORD

Prev Next

Use this command to upload the SSH log file to the TFTP Server.

Ensure the following before using this command:

  • The TFTP Server IP address must be set using the command set tftpserver ip <server_ip>
  • Ensure the file with the corresponding file name exists on the TFTP Server with write permissions for all.

The file uploaded on the TFTP Server is the TAR file containing one or more zipped files. Perform the following steps to access the files:

  • Untar the file using the command tar –xvf <filename> to get the individual zipped files.
  • Each file must be unzipped using the command gunzip <zipped_file> to view the file.

Syntax:

sshlogupload <filename>

A sample SSH log message is displayed below:

Sep 16 09:09:52 localhost kernel: SSHD_DROP:IN=eth0 OUT= MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 SRC=172.16.232.47 DST=172.16.199.89 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=4286 DF PROTO=TCP SPT=2821 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0

Log Message Fields Description
SSHD_DROP Denotes the number of minutes for activating the performance debugging on the Sensor
IN=etho Interface the packet was received from; empty value for locally generated packets
OUT= Interface the packet was sent to; empty value for locally received packets
MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00

The MAC field consisting of 14 entities, separated by colons, and this can read as the following:

Dest MAC= 00:06:92:25:9d:80 — The destination MAC address

Src MAC=00:0b:bf:a1:b7:fc — The source MAC address

Type=08:00 — Ethernet frame carrying an IPv4 datagram

SRC=172.16.232.47 The source IP address
DST=172.16.199.89 The destination IP address
LEN=48 The total length of IP packet in bytes
TOS=0x00 The Type Of Service, “Type” field
PREC=0x00 The Type Of Service, “Precedence” field
TTL=127 The remaining Time To Live is 127 hops
ID=4286 The unique ID for this IP datagram shared by all fragments, if fragmented
DF Do not Fragment flag
PROTO=TCP The protocol name
SPT=2821 The source port
DPT=22 The destination port
WINDOW=65535 The number of bits specified on the “Window Scale” TCP option
RES=0x00 The reserved bits
SYN The synchronize flag and is only exchanged at TCP connection establishment
URGP=0 The urgent flag

Applicable to:

NS-series Sensors