Configure event sinks

Prev Next

Events are stored at locations called event sinks. You can add, view, or remove an event.

You can log events in many types of event sinks, including:

  • Operating system log (oslog)
  • System controller (sc)

    Note

    When sc event sink is enabled, it sends the events to Trellix ePO - On-prem.

  • Debug output (debuglog)
  • Pop-up (Windows only)

You can review the event sinks details and add or remove events as needed.

Task Command Description
Add an event sadmin event sink -a <event_name> <sink_name> Add an event by specifying both the event name and the event sink where you want to log the event. The specified event is added to the event sink.
View the event sink details sadmin event sink View the event sink details for all events generated in the system. You can view the associated event sinks for each event. Event sink details configured in the system for all events are listed.
Remove an event sadmin event sink -r <event_name> <sink_name> Remove an event by specifying both the event name and the event sink from where you want to remove the event. Removing an event from an event sink allows you to stop logging the event to that event sink.