The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Audit logging

Prev Next

Audit logging is implemented to meet the Common Criteria standards.

Trellix ESM audit logging is implemented by creating an Internal events.

Advantages of capturing Audit Log actions in the Alert table:

  • The view or report creation and filtering features can be used to find audit log-specific events.

  • The Policy Editor interface can be used to manage the types of audit actions that are logged, by turning on or off rules.

  • The backup can be used to archive audit logs.

Audit log data

The Alert record contains:

  • The user's session.

  • The originating IP address.

  • The affected device.

  • The dsID and sigID part of a signature.