The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Templates for syslog, email, and pager

Prev Next

If you are parsing the notifications sent through email, script, or pager, Trellix recommends that you define your custom message template. Default template may change in newer releases and it may break your parsing algorithms.

The following tables describe the variables used in the various message templates.

Note

“%” "/” and "$" are reserved characters. Do not use them as a delimiter in custom templates.

Variable name Description
ALERT_ID Unique ID assigned to an alert by the Manager
ALERT_TYPE The type of the attack that triggered the alert. The value, for example, can be exploit, host sweep, or port scan.
ATTACK_TIME Time when the attack was detected
ATTACK_NAME Name of the attack that triggered the alert
ATTACK_ID The Trellix IPS ID for the attack
ATTACK_SEVERITY System impact severity posed by the attack: high, medium, low, or informational
ATTACK_SIGNATURE Signature that matched the attack traffic (applicable only to signature-based attacks)
ATTACK_CONFIDENCE Higher the confidence, the lower is the chance for the attack to be a false-positive.
ADMIN_DOMAIN The admin domain to which the Sensor that detected the attack belongs
ATTACK_COUNT The number of times the attack was detected within the throttle duration
SENSOR_NAME The Sensor that detected the attack
INTERFACE The Sensor's interface where the attack was detected
SENSOR_CLUSTER_MEMBER The Sensor in a fail-over pair that detected the attack
SOURCE_IP IP address of the host from where the attack originated
SOURCE_PORT The source port number of the attack traffic
DESTINATION_IP IP address of the targeted host
DESTINATION_PORT The destination port number of the attack traffic
CATEGORY General attack type
SUB_CATEGORY Within the attack type, a specific classification such as virus and Trojan horse
DIRECTION Whether the traffic was inbound or outbound
RESULT_STATUS Whether the attack was successful, blocked, or a failed attempt
DETECTION_MECHANISM The method used to detect the attack. Each method relates to a specific attack category. Some of these methods are signature, threshold, statistical anomaly, and flow correlation.
APPLICATION_PROTOCOL The application protocol found in the attack traffic
NETWORK_PROTOCOL The transport protocol used for the attack traffic
RELEVANCE Information whether the attack is relevant for the targeted host based on information from McAfee Vulnerability Manager
QUARANTINE_END_TIME Time when an attacking host will be out of quarantine
SENSOR_ALERT_UUID Unique ID assigned to an alert by the Sensor
SOURCE_VM_ESX_NAME The VMware ESX server that hosts the VMware from which the attack traffic originated
SOURCE_VM_NAME The VMware host from which the attack traffic originated
TARGET_VM_NAME The targeted VMware host for the attack
TARGET_VM_ESX_NAME The VMware ESX server that hosts the targeted VMware
URI_INFO

The URI found in the attack traffic

VLAN_ID The VLAN tagged with the attack traffic
DEST_APN Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the targeted mobile equipment

DEST_IMSI Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment

DEST_PHONE_NUMBER Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the targeted mobile equipment

SRC_APN Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic

SRC_IMSI Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment

SRC_PHONE_NUMBER Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the source mobile equipment

LAYER_7_DATA The application-layer data found in the attack traffic
ZONE_NAME Zone from which the alert was raised; applicable only for NTBA alerts
SOURCE_OS Source OS name
DEST_OS Destination OS name
MALWARE_FILE_TYPE Malware file type
MALWARE_FILE_LENGTH Malware file length
MALWARE_FILE_NAME Malware file name
MALWARE_FILE_MD5_HASH Malware file MD5 hash
MALWARE_VIRUS_NAME Malware virus name
MALWARE_CONFIDENCE Malware confidence
MALWARE_DETECTION_ENGINE Malware detection engine

The following table describes the fault template variables.

Name Description
ADMIN_DOMAIN The admin domain associated with the fault message
FAULT_NAME Name of the fault
FAULT_TYPE The state of the fault, whether it is created, acknowledged, or cleared
OWNER_ID The Sensor ID where the fault occurred. This field is not applicable to Manager faults.
OWNER_NAME The user-defined name of the Sensor where the fault occurred. For Manager fault, the value is 'Manager.'
FAULT_LEVEL The level of the fault. Whether it occurred at the Manager system level, Sensor level, or Sensor interface level.
FAULT_TIME Timestamp of when the fault occurred
FAULT_SOURCE Whether the fault was sent by the Sensor to the Manager or it was generated by the Manager
FAULT_COMPONENT The component where the fault occurred
SEVERITY Whether the fault is critical, an error, warning, informational, or unknown
DESCRIPTION The description as found in the faultNameAndText.properties file
ACK_INFORMATION If true, the fault has been acknowledged by someone.
SENSOR_NAME The user-defined name of the Sensor where the fault occurred

The following table describes Firewall access rule template variables.

Name Description
SENSOR_NAME The Sensor that parsed the traffic matching the Firewall access rule
ADMIN_DOMAIN The admin domain to which the Sensor belongs
INTERFACE The interface where the matching traffic was detected
ACL_ACTION Whether the traffic was inspected, dropped, denied, or ignored
SOURCE_IP The IP address of the host from which the traffic originated
SOURCE_PORT The source port number of the traffic that matched the Firewall access rule
DESTINATION_IP The IP address of the destination host for the traffic
DESTINATION_PORT The destination port number of the traffic that matched the Firewall access rule
APPLICATION_PROTOCOL The layer 7 protocol associated with the traffic that matched the Firewall access rule
NETWORK_PROTOCOL The IP protocol that matched
ALERT_DURATION The number of Firewall syslog messages that were suppressed
ALERT_COUNT The number of Firewall syslog messages that were forwarded
ALERT_DIRECTION Whether the traffic that matched was inbound or outbound
APPLICATION The layer 7 application associated with the matched traffic
ACL_DESCRIPTION The user-entered description of the Firewall policy
SOURCE_HOSTNAME The host DNS name from which the traffic originated
DESTINATION_HOSTNAME The host DNS name to which the traffic is destined
SOURCE_COUNTRY The country from which the traffic originated
DESTINATION_COUNTRY The country to which the traffic is destined to
ACL_POLICY The name of the Firewall policy
ACL_RULE_NUMBER The order of the rule in the effective list of Firewall access rules