The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

sshlogupload WORD

Prev Next

Use this command to upload the SSH log file to the TFTP Server.

Ensure the following before using this command:

  • The TFTP Server IP address must be set using the command set tftpserver ip <server_ip>

  • Ensure the file with the corresponding file name exists on the TFTP Server with write permissions for all.

The file uploaded on the TFTP Server is the TAR file containing one or more zipped files. Perform the following steps to access the files:

  • Untar the file using the command tar –xvf <filename> to get the individual zipped files.

  • Each file must be unzipped using the command gunzip <zipped_file> to view the file.

Syntax:

sshlogupload <filename>

A sample SSH log message is displayed below:

Sep 16 09:09:52 localhost kernel: SSHD_DROP:IN=eth0 OUT= MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 SRC=172.16.232.47 DST=172.16.199.89 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=4286 DF PROTO=TCP SPT=2821 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0

Log Message Fields

Description

SSHD_DROP

Denotes the number of minutes for activating the performance debugging on the Sensor

IN=etho

Interface the packet was received from; empty value for locally generated packets

OUT=

Interface the packet was sent to; empty value for locally received packets

MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00

The MAC field consisting of 14 entities, separated by colons, and this can read as the following:

Dest MAC= 00:06:92:25:9d:80 — The destination MAC address

Src MAC=00:0b:bf:a1:b7:fc — The source MAC address

Type=08:00 — Ethernet frame carrying an IPv4 datagram

SRC=172.16.232.47

The source IP address

DST=172.16.199.89

The destination IP address

LEN=48

The total length of IP packet in bytes

TOS=0x00

The Type Of Service, “Type” field

PREC=0x00

The Type Of Service, “Precedence” field

TTL=127

The remaining Time To Live is 127 hops

ID=4286

The unique ID for this IP datagram shared by all fragments, if fragmented

DF

Do not Fragment flag

PROTO=TCP

The protocol name

SPT=2821

The source port

DPT=22

The destination port

WINDOW=65535

The number of bits specified on the “Window Scale” TCP option

RES=0x00

The reserved bits

SYN

The synchronize flag and is only exchanged at TCP connection establishment

URGP=0

The urgent flag

Applicable to:

NS-series Sensors