The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the Connection Event Logs

Prev Next

You can view the connection event logs using the Network Security appliance CLI:

The Network Security appliance displays the connection event log details about SSL flows based on SSL interception traffic it observes. Viewing log details on SSL flows can help you to identify specific trends or patterns in SSL interception traffic.

The following table describes the log fields that are tracked by the Network Security appliance for each connection event:

Field

Description

Date

Date that the connection event is logged.

Time

Time that the connection event is logged.

c_ip

IP address of the client.

c_port

Port number of the client.

s_ip

IP address of the server.

s_port

Port number of the server.

cs_bytes

Client-side bytes transferred during the connection and logged.

rs_bytes

Server-side bytes transferred during the connection and logged.

cs_tls_version

TLS version required for client-side connections.

rs_tls_version

TLS version required for server-side connections.

cs_cipher_suite

Cipher suite associated with client-side connections.

rs_cipher_suite

Cipher suite associated with server-side connections.

rs_cert_common_name

Common name of the server-side certificate.

action

Whether the connection was decrypted, whitelisted, or blocked due to an attack seen in decrypted content.

s_site_name

Server name identification (SNI) sent by the client or server

error

Types of error codes for connection events:

  • 71 Protocol Error—For example, the requested URL could not be retrieved.

  • sslv3 alert handshake failure—For example, server certificate expired or an incorrect certificate was configured.

Prerequisites