The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Backfill events

Prev Next

When Logon Tracker first runs on an endpoint, it can parse existing logs to identify the logon history for that endpoint. Backfill is enabled by default.

Note

Disabling backfill is not recommended.

Capturing historical logon activity is critical to investigating lateral movement.

Disabling event enrichment

When the Disabling Event Enrichment setting is turned on, it will disable advanced enrichment on the endpoints. Advanced enrichment uses multiple sources of event data to enhance events with additional metadata. Disabling the advanced enrichment improves performance of the endpoint.

Maximum cache size

The Maximum Cache Size setting controls the maximum number of unique events the endpoint will hold in its cache before older events are removed. This setting directly affects the memory footprints of the endpoint for the Logon Tracker process. The default cache size is 5,000,000 unique events.