The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How log search works

Prev Next

Use the log search view to search log data when at least one Trellix Enterprise Security Manager - Enterprise Log Manager exists on the system. It allows you to perform more detailed searches and provides real-time tracking of search progress and results when you perform a search of logs on one or more Trellix Enterprise Security Manager - Enterprise Log Manager.

This view provides real-time information about the amount of data that must be searched, allowing you to limit the query to minimize the number of files to be searched.

During the search, the graphs show the estimated results:

  • Results Time Distribution graph — Displays the estimates and results based on a time distribution. The bottom axis changes depending on what is selected in the time frame drop-down list.

  • Data Source Results graph — Displays the estimates and results per data source based on the data sources of the devices selected on the system navigation tree.

  • Device Type Results graph — Displays the estimates and results per device type based on the devices selected on the system navigation tree.

The system populates these graphs before the search begins and updates the graphs as results are found. You can select one or more bars on the Data Source Results or Device Type Results graphs, or highlight a section of the Results Time Distribution graph.

Click Apply Filters to narrow the search once the results have started coming in. This allows you to drill down to the search results, and to limit the amount of data that needs to be searched. When the search is finished, these graphs display the actual results.