The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure SNMP notifications

Prev Next

To configure device-generated SNMP notifications, you must define which traps to send and their destinations.

Note

If you set up SNMP on a high availability (HA) Trellix Enterprise Security Manager - Event Receiver, the traps for the primary Trellix Enterprise Security Manager - Event Receiver go out through the shared IP address. So, when you set up the listeners, set one up for the shared IP address.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select the device and click Settings.png.

  3. Click SNMP Configuration.

  4. SNMP Requests tab:

    • Set the requests to be accepted.

    • Indicate whether to allow SNMP traffic:

      • For SNMP version 1 and version 2 traffic, set the community string.

      • For SNMP version 3 traffic, select the security level, authentication protocol, and privacy protocol.

    • Show the IP addresses that the device allows or considers trusted. You can add new addresses and edit or remove existing ones. The IP address can include a mask.

      Note

      A trusted IP address must be present.

    • View the Trellix MIB, which defines the object identifiers (OIDs) for each object or characteristic of interest.

  5. SNMP Traps tab:

    • Set the port where the cold/warm trap traffic, block list entry, and link up/link down traffic passes.

    • Send Link Up and Link Down traps. If you select this feature and are using multiple interfaces, you are notified when an interface goes down and when it comes back up.

      Note

      Cold/warm trap traffic is automatically allowed. A cold start trap is generated when there is a hard shut-down or hard reset. A warm start trap is generated when you reboot the system.

    • Send an SNMP trap when the database (cpservice, IPSDBServer) goes up or down.

    • Send an SNMP trap when a log is not written to the log table.

    • Set the system profile names where you want the notifications sent. The table shows all available SNMP trap profiles on the system.