The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Forwarding events with Standard Event Format

Prev Next

Standard Event Format (SEF) is a JavaScript Object Notation (JSON)-based event format to represent generic event data. SEF format forwards events from one Trellix ESM to a receiver on a different Trellix ESM, and from the Trellix ESM to a third party. You can also use it to send events from a third party to a receiver by selecting SEF as the data format when creating the data source.

When setting up event forwarding with SEF from one Trellix ESM to another Trellix ESM, complete the following steps:

  1. From the Trellix ESM that is forwarding the events, export data sources, custom types, and custom rules.

  2. On the Trellix ESM with the receiver you are forwarding events to, import the data sources, custom types, and custom rules that you exported.

  3. On the Trellix ESM receiving the events from another Trellix ESM, add a Trellix ESM data source.

  4. On the sending Trellix ESM, add the event forwarding destination as follows:

    • From the Trellix ESM dashboard, click menu.png and select More Settings.

    • On the system navigation tree, select Trellix ESM and click Settings.png.

    • Click Event Forwarding, then click Add.

    • On the Add Event Forwarding Destination page, select syslog (Standard Event Format) in the Format field, then complete the remaining fields with the information for the Trellix ESM you are forwarding to, and click OK.