The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Logon Timeout

Prev Next

The logon timeout sets the number of minutes to cache unique events. The uniqueness of an event is determined by the following:

  • Source metadata (account name, host name, IP address)

  • Target metadata (account name, host name, IP address)

  • Event metadata

  • Process Path

By default, the timeout is 24 hours (1440 minutes). When the timeout is set to 0, caching is disabled.

Note

It is always recommended not to disable the cache.

Some log sources are extremely verbose, and the cache is imperative to reducing the data set on the Server. As an example, it is not uncommon to observe a Windows Server generate duplicate event logs several times within a four-hour period. The only scenario where disabling the cache can be useful is on the Agent deployments to a limited number of systems (example: in a test lab).