The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure a Trellix Enterprise Security Manager - Enterprise Log Search device

Prev Next

Add Trellix ESM - ELS devices to the console, set up Trellix ESM - ELS storage and retention policies, and associate data sources with specific retention policies.

Set up and install virtual or physical devices.

  1. From the Trellix ESM dashboard, click and select More Settings .

  2. Add Trellix ESM - ELS devices to the console.

    1. On the actions toolbar, click GUID-66CEDB9A-A83B-4A7F-AFF3-F5DB2E974859-low.png, then select Enterprise Log Search then click Next.

    2. Enter a unique device name, then click Next.

    3. Enter the target IP address or URL, target SSH port number, and Network Time Protocol (NTP) settings for the device then click Next.

    4. Enter a password for this device, then click Next.

  3. Set up storage.

    Note

    Retaining uncompressed data speeds the Trellix ESM - ELS search capabilities, but it requires more storage space, such as hard drives or network storage.

    1. Select Trellix ESM-ELS, click GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png, then click Data Storage.

    2. If using iSCSI, Trellix DAS, SAN, or virtual local drives, fill in the information in the top grid.

    3. If using SAN, virtual local, NFS, iSCSI, or CIFS, click Add in the lower grid.

    4. Enter the correct parameters and click OK.

  4. Add retention policies (limited to no more than 6).

    Note

    To search Trellix ESM-ELS log data, you must have at least one retention policy. The system sets the first retention policy created as the default. If only one policy exists, you can change it but you can't delete it. The Trellix ESM-ELS accepts data up to six months older than the date that you created the first retention policy.

    1. Select Trellix ESM-ELS, click GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png, then click Retention Policies.

    2. Click Add.

    3. Specify the name and duration of the retention policy and click OK.

      Note

      The system stores duration in days. You can set up a duration in years (365 days), quarters (90 days), or months (30 days).

  5. Associate data sources with retention policies.

    1. Select the data source device (such as a Trellix Enterprise Security Manager - Event Receiver) and click GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png.

    2. Click Data Sources.

    3. In the Logging column, choose the relevant checkbox to display the Log Data Options screen.

    4. Select the retention policy you want to associate with this data source and click OK.

The Trellix ESM - ELS makes data available for searching.