The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Cache hits

Prev Next

As discussed in the Logon timeout section, the uniqueness of an event is determined by various source and target attributes of a logon. When the Logon Tracker endpoint module observes a duplicate logon, an internal cache is incremented. If the Logon Timeout has expired, the event is then published to the server to include the number of cache hits (that is, the total number of times a duplicate event has been observed on the endpoint). This count is exposed in the UI grid view in the “Cache Hits” column. Cache Hits can be a useful data point when investigating lateral movement as it implies the uniqueness of an event.