The Audit Log workspace provides centralized visibility to trace administrative, user, and system events across the Trellix ePO - SaaS platform. With a modernized interface, administrators can review and investigate activities across the ePO - SaaS platform and troubleshoot issues faster.
With Audit Log, you can:
Note
The Audit Log is currently available to customers in the US and EU regions only.
Investigate activity in the Audit log
Filter entries by time range, product suite, or saved query criteria to identify specific system actions across your environment.
Prerequisites
Ensure you are assigned a role with permissions to view ePO - SaaS reports.
Select Menu → Reporting → Audit Log (New).
Review the activity logs in the table based on the selected time range.
Option
Description
Event Summary
Identifies the event category and type.
Actor Summary
Identifies the ID, name, and account type of the user or service.
Action Summary
Identifies the action name and operation type.
Affected Resource Summary
Displays the impacted resource types and total count.
Action Interval
Identifies the start time, end time, and execution duration.
Action Detail Summary
Displays the system descriptive message.
Action Severity
Displays the Low or High severity level indicator.
Affected Resource Summary
Displays the resource ID, resource count, resource type, and resource name affected by the change. For logs involving a policy or configuration change, click View more to view a side-by-side comparison showing exactly what was modified.
You can further filter the list by applying below filters:
Time Range: Select a preset range or select Custom to specify UTC dates.
Provider Suite and Provider App: Select a specific Trellix product suite or module.
Basic Filter: Enable the toggle and select a saved filter set.
Refresh: Click Refresh at the top right to load the newest entries. This also updates the Provider App list with the latest available options for your tenant.
Click a column header to sort table entries. For multi-field columns such as Action Interval, select Start Time, End Time, or Execution Time to sort.
Build custom filters for detailed investigations
Create a customized filter to perform specific administrative or user actions.
Select Menu → Reporting → Audit Log (New).
Select Match All to enforce all criteria, or select Match Any to enforce at least one.
Click + Add Filter. The toggle switches from Basic Filter to Advanced Filters automatically.
Configure the filter parameters:
Select Attribute: Choose the target database attribute.
Select Operator: Choose the evaluation operator.
Select Value: Enter or select the target value.
Click + Add Filter again to add more conditions.
Click Apply to execute the filter, or click Save to save the filter for reuse. Click Clear All to remove all conditions.
To search for specific text within an attribute, click + Add Filter, select the attribute you want to search, select = equals as the operator, then enter the value to match. Example: To find entries containing specific text in the action message, select Action Message as the attribute, then enter the text you want to search for. This filters entries where the Action Detail Summary column matches.
Customize your Audit Log display view
Modify log table columns to focus on details relevant to your investigation.
Select Menu → Reporting → Audit Log (New).
Click the table settings icon and select Customize Columns to open the Primary Audit Columnset panel.
Click Save to update the current view, click Save As to create a named layout, or click Reset to restore default columns.
Click the table settings icon and select Hide Empty Columns to remove fields containing no data.
Select an item from the Columnset drop-down menu to switch between saved layouts.
Monitor activity trends with visual analytics
Switch to Visualization to see how activity breaks down by severity, actor and status. This makes it easier to spot unusual spikes and patterns across your tenant.
Select Menu → Reporting → Audit Log (New).
Enable Visualization.
Review the following:
Time Range Overview: Displays the active evaluation window and refreshes timestamps.
Breakdown Cards: Displays distribution metrics for Provider Suite, Provider App, Action Severity, Resource Type, Actor Type, and Action Status.
Select Daily, Weekly, or Monthly on a card to change the data window and refresh frequency:
Daily: Shows data for the last 1 day (12 AM to 12 AM) and refreshes in the background every 6 hours.
Weekly: Shows data for the last 7 days and refreshes in the background once a day.
Monthly: Shows data for the current calendar month (the 1st through the end of the month) and refreshes in the background once every 7 days.
Note
Audit Log entries are retained for 12 months. Entries older than this period are not available for review or visualization.