The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Auto writeout

Prev Next

Automatically writes the data source setting to the Trellix Enterprise Security Manager - Event Receiver on upgrade.

This feature writes out to the device when the following conditions are met:

  • Device upgraded before write out (for high availability, both the devices must be upgraded).

  • Device is not disabled.

    Note

    If the device is disabled before upgrade, the auto write also be disabled and user has to manually write out.

  • Device is keyed.

It checks the conditions for each device in every 5 minutes. The system continuously tries to write out data sources until it succeeds. To view the AutoWriteout logs, enable policyDebug using ToggleDebug -f "policyDebug=1". The logs are found in /var/log/messages.

During auto writeout data sources, the following devices are auto write:

  • Trellix Enterprise Security Manager - Event Receiver

  • Trellix Application Data Monitor

  • RECELM (Trellix Enterprise Security Manager - Event Receiver and Trellix Enterprise Security Manager - Enterprise Log Manager)

  • Trellix ESM - ACE

When the user clicks the Write option in the Data Sources page and a write is already in progress, an error 90 (Job already exists) is displayed. For more information, see KB94427.