The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Logon Collector - Integration issues

Prev Next

To ensure connectivity between the Trellix Logon Collector and Manager, the following configurations are mandatory.

  • Ensure that the Active Directory services are up and running. If the Active Directory (AD) is not configured correctly or down, the Manager does not receive Logon Collector updates and test connectivity does not get verified.

  • Add the domain that needs to be monitored in the Logon Collector server. If the domain is not added, test connection fails and the Manager does not receive Logon Collector updates.

  • Ensure that all Logon Collector components of the Logon Collector server are running.

  • While exchanging Logon Collector certificate with the Manager by pasting, ensure that you copy the certificate content to Notepad to remove any inadvertent spaces that might cause certificate exchange failure during connectivity.

  • To verify that Manager is receiving Logon Collector updates, create a Firewall and then double-click the Source User field to verify that the Groups are configured in the AD.

As a part of the Manager-Sensor and Logon Collector Integration, the Manager sends IP User mapping and User-Group mapping periodically on certain well defined events. The Sensor receives the Logon Collector updates from the Manager only when user-based Firewall policies are assigned to Sensors. Manager notifies the following two faults related to this integration which will be available in the System Fault page:

  • Number of user configured in AD is more than 75000 or IP-user mapping is more than 100,000.

  • TLC bulk update file exceeds 25mb limit which is a critical fault and user intervention is needed.