The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Telemetry

Prev Next

The purpose of telemetry is to facilitate you in providing helpful information to Trellix about your usage of Trellix IPS solution so that Trellix in turn optimizes your protection. Telemetry data analysis empowers Trellix with essential monitoring and reporting capabilities, and assists the company in gaining valuable business intelligence insights and enhancing threat intelligence capabilities.

Currently, the IPS Manager collects two types of telemetry data with user's content and sends to Trellix telemetry servers at different intervals:

  • Threat telemetry data: Threat telemetry comprises data related to alerts that enables Trellix to proactively identify and mitigate security risks.

  • Device telemetry data: Device telemetry comprises a comprehensive set of information, including general setup, Virtual IPS cluster usage details, fault summary, and license information.

    Note

    Virtual IPS cluster usage details and license information are necessary for Trellix business intelligence and sent automatically to Trellix telemetry servers on a daily basis.

When the Manager is registered with Trellix using the Trellix IPS Registration Key, the Telemetry pop-up window appears in which you can configure the threat and device-specific data you want to send to Trellix and save the changes. If you wish to change the telemetry configurations later, you can do so from Manager → <Admin Domain Name → Setup → Telemetry page.

You can find details about the IPS telemetry data being uploaded to Trellix telemetry servers at different intervals from the ems.log file, or check for the same log entries in the Manager → <Admin Domain Name → Troubleshooting → Logs → System Files page. You can also track the status of telemetry data uploading and saving on the User Activities tab, and look for errors related to the same on the Faults tab in the Manager → <Admin Domain Name → Troubleshooting → Logs page.

Note

  • IPS telemetry data is stored in the telemetry servers for an indefinite period.

  • For more information on the usage of telemetry data by Trellix GTI and Trellix Insights, see the chapters Integration with Trellix Global Threat Intelligence and Integration with Trellix Insights in Trellix Intrusion Prevention System Integration Guide.