The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Receiver data archiving

Prev Next

Forward a backup of the raw data to your storage device for long-term storage.

Trellix ESM supports the following types of storage:

  • Server Message Block/Common Internet File System (SMB/CIFS)

  • Network File System (NFS)

  • Syslog Forwarding

SMB/CIFS and NFS store, in the form of data files, a backup of all raw data sent to the receiver by data sources.

Syslog Forwarding sends raw data for syslog events as a continuous stream of combined syslogs to the device. It supports only UDP packets.

The receiver can forward to only one type of storage at a time; you can configure all three types, but only one type can be enabled to archive data

Note

This feature doesn't support NetFlow, sflow, or IPFIX data source types.

To set up receiver data archiving, see Trellix Enterprise Security Manager Installation Guide.