The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Templates for syslog, email, and pager

Prev Next

If you are parsing the notifications sent through email, script, or pager, Trellix recommends that you define your custom message template. Default template may change in newer releases and it may break your parsing algorithms.

The following tables describe the variables used in the various message templates.

Note

“%” "/” and "$" are reserved characters. Do not use them as a delimiter in custom templates.

Variable name

Description

ALERT_ID

Unique ID assigned to an alert by the Manager

ALERT_TYPE

The type of the attack that triggered the alert. The value, for example, can be exploit, host sweep, or port scan.

ATTACK_TIME

Time when the attack was detected

ATTACK_NAME

Name of the attack that triggered the alert

ATTACK_ID

The Trellix IPS ID for the attack

ATTACK_SEVERITY

System impact severity posed by the attack: high, medium, low, or informational

ATTACK_SIGNATURE

Signature that matched the attack traffic (applicable only to signature-based attacks)

ATTACK_CONFIDENCE

Higher the confidence, the lower is the chance for the attack to be a false-positive.

ADMIN_DOMAIN

The admin domain to which the Sensor that detected the attack belongs

ATTACK_COUNT

The number of times the attack was detected within the throttle duration

SENSOR_NAME

The Sensor that detected the attack

INTERFACE

The Sensor's interface where the attack was detected

SENSOR_CLUSTER_MEMBER

The Sensor in a fail-over pair that detected the attack

SOURCE_IP

IP address of the host from where the attack originated

SOURCE_PORT

The source port number of the attack traffic

DESTINATION_IP

IP address of the targeted host

DESTINATION_PORT

The destination port number of the attack traffic

CATEGORY

General attack type

SUB_CATEGORY

Within the attack type, a specific classification such as virus and Trojan horse

DIRECTION

Whether the traffic was inbound or outbound

RESULT_STATUS

Whether the attack was successful, blocked, or a failed attempt

DETECTION_MECHANISM

The method used to detect the attack. Each method relates to a specific attack category. Some of these methods are signature, threshold, statistical anomaly, and flow correlation.

APPLICATION_PROTOCOL

The application protocol found in the attack traffic

NETWORK_PROTOCOL

The transport protocol used for the attack traffic

RELEVANCE

Information whether the attack is relevant for the targeted host

QUARANTINE_END_TIME

Time when an attacking host will be out of quarantine

SENSOR_ALERT_UUID

Unique ID assigned to an alert by the Sensor

SOURCE_VM_ESX_NAME

The VMware ESX server that hosts the VMware from which the attack traffic originated

SOURCE_VM_NAME

The VMware host from which the attack traffic originated

TARGET_VM_NAME

The targeted VMware host for the attack

TARGET_VM_ESX_NAME

The VMware ESX server that hosts the targeted VMware

URI_INFO

The URI found in the attack traffic

VLAN_ID

The VLAN tagged with the attack traffic

DEST_APN

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the targeted mobile equipment

DEST_IMSI

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment

DEST_PHONE_NUMBER

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the targeted mobile equipment

SRC_APN

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic

SRC_IMSI

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment

SRC_PHONE_NUMBER

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the source mobile equipment

LAYER_7_DATA

The application-layer data found in the attack traffic

ZONE_NAME

Zone from which the alert was raised; applicable only for NTBA alerts

SOURCE_OS

Source OS name

DEST_OS

Destination OS name

MALWARE_FILE_TYPE

Malware file type

MALWARE_FILE_LENGTH

Malware file length

MALWARE_FILE_NAME

Malware file name

MALWARE_FILE_MD5_HASH

Malware file MD5 hash

MALWARE_VIRUS_NAME

Malware virus name

MALWARE_CONFIDENCE

Malware confidence

MALWARE_DETECTION_ENGINE

Malware detection engine

The following table describes the fault template variables.

Name

Description

ADMIN_DOMAIN

The admin domain associated with the fault message

FAULT_NAME

Name of the fault

FAULT_TYPE

The state of the fault, whether it is created, acknowledged, or cleared

OWNER_ID

The Sensor ID where the fault occurred. This field is not applicable to Manager faults.

OWNER_NAME

The user-defined name of the Sensor where the fault occurred. For Manager fault, the value is 'Manager.'

FAULT_LEVEL

The level of the fault. Whether it occurred at the Manager system level, Sensor level, or Sensor interface level.

FAULT_TIME

Timestamp of when the fault occurred

FAULT_SOURCE

Whether the fault was sent by the Sensor to the Manager or it was generated by the Manager

FAULT_COMPONENT

The component where the fault occurred

SEVERITY

Whether the fault is critical, an error, warning, informational, or unknown

DESCRIPTION

The description as found in the faultNameAndText.properties file

ACK_INFORMATION

If true, the fault has been acknowledged by someone.

SENSOR_NAME

The user-defined name of the Sensor where the fault occurred

The following table describes Firewall access rule template variables.

Name

Description

SENSOR_NAME

The Sensor that parsed the traffic matching the Firewall access rule

ADMIN_DOMAIN

The admin domain to which the Sensor belongs

INTERFACE

The interface where the matching traffic was detected

ACL_ACTION

Whether the traffic was inspected, dropped, denied, or ignored

SOURCE_IP

The IP address of the host from which the traffic originated

SOURCE_PORT

The source port number of the traffic that matched the Firewall access rule

DESTINATION_IP

The IP address of the destination host for the traffic

DESTINATION_PORT

The destination port number of the traffic that matched the Firewall access rule

APPLICATION_PROTOCOL

The layer 7 protocol associated with the traffic that matched the Firewall access rule

NETWORK_PROTOCOL

The IP protocol that matched

ALERT_DURATION

The number of Firewall syslog messages that were suppressed

ALERT_COUNT

The number of Firewall syslog messages that were forwarded

ALERT_DIRECTION

Whether the traffic that matched was inbound or outbound

APPLICATION

The layer 7 application associated with the matched traffic

ACL_DESCRIPTION

The user-entered description of the Firewall policy

SOURCE_HOSTNAME

The host DNS name from which the traffic originated

DESTINATION_HOSTNAME

The host DNS name to which the traffic is destined

SOURCE_COUNTRY

The country from which the traffic originated

DESTINATION_COUNTRY

The country to which the traffic is destined to

ACL_POLICY

The name of the Firewall policy

ACL_RULE_NUMBER

The order of the rule in the effective list of Firewall access rules