Audit logging is implemented to meet the Common Criteria standards.
Trellix ESM audit logging is implemented by creating an Internal events.
Advantages of capturing Audit Log actions in the Alert table:
The view or report creation and filtering features can be used to find audit log-specific events.
The Policy Editor interface can be used to manage the types of audit actions that are logged, by turning on or off rules.
The backup can be used to archive audit logs.
Audit log data
The Alert record contains:
The user's session.
The originating IP address.
The affected device.
The dsID and sigID part of a signature.