A number of Trellix DLP Network - SaaS events are available in the Client Events page in ePO - SaaS. You can get additional information from the on-box syslog and a remote logging server if you have one enabled. The Client Events page also displays Appliance Management events.
Client Events
Go to the System Tree, and select the appliance for which you want to see the events. Select Actions, then go to Agent → Show Client Events. Some events include reason codes that you can use to search log files.
Tip
Regularly purge the Client Events page to stop it from becoming full.
Event ID | UI event text | Description |
|---|---|---|
15001 | LDAP query failure | The query failed. Reasons are provided in the event descriptions. |
15007 | LDAP directory synchronization | Directory synchronization status. |
185001 | DLP scanning policy | Policy scanning events with reason codes:
|
210003 | Resource usage reached critical level | Trellix DLP Network Prevent – SaaS can't analyze a message because the directory is critically full. |
210900 | Appliance ISO upgrade success Appliance ISO upgrade failed Appliance downgrading to lower version Internal install image updated successfully Failed to update internal install image | Appliance upgrade events with reason codes:
Internal installation image updates using SCP events:
|
220000 | User logon | User log-on events with reason codes:
|
220001 | User logoff | User log off events with reason codes:
|
220900 | Certificate Install |
A certificate might not get installed due to one of the following reasons:
The reason is also reported in the syslog. If the reason does not match any of the available reasons, it gives the default Certificate installation failed event. |
240155 | Capture PII Deletion | Personal data deletion succeeded. |
244005 | Misconfigured Trellix Logon Collector | Trellix Logon Collector client has an invalid configuration. |
244006 | Certificate rejected by MLC Server | Certificate rejected by Trellix Logon Collector. |
244007 | MLC client has started | Trellix Logon Collector client has started. |
244008 | MLC client has stopped | Trellix Logon Collector client has stopped. |
244009 | MLC client has been restarted | Trellix Logon Collector client has restarted. |
244010 | Invalid MLC certificate BER/DER data | The certificate is not base64 encoded. |
244011 | Illegal MLC Certificate footer | The certificate footer is not valid. |
244012 | Illegal MLC Certificate header | The certificate header is not valid. |
244013 | Extra data given to DerValue constructor | SSL error using certificate file. |
244014 | MLC | Trellix Logon Collector synchronization complete. |
300000 | Channel Event | Send a heartbeat signal to all channels. |