The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Search controls

Prev Next
Date: year, month and day

This represents the date to start the search from. It defaults to the most recent timestamp received from the agent. This is a drop-down automatically configured based on oldest and newest timestamps from the agents.

Time period

The default is 1 month prior. Searches are bounded to predefined periods of 1 day, 1 week, a fortnight, 1 month, 3 months, 6 months, 1 year and all data.

Privilege level

Used to identify logons by privileged accounts. Supports the following predefined options:

  • Local Admin – The endpoint user belongs to the local administrators group for Windows or the `root`, wheel`, or `sudo` group for Linux.

  • Domain Admin – User belongs to any of the following privileged domain groups: Enterprise Admins, Schema Admins, Administrators, Domain Admins, Server Operators, Account Operators, and DS Restore Mode Administrator.

    Note

    This option is provided as a convenience function. It allows quick identification of accounts belonging to known privileged groups.

  • Privileged – On Windows, when a privileged account logs into a system, it is explicitly annotated in the Windows Security Event log as “privileged” through the generation of a Windows Event 4672. Logon Tracker identifies these logons and annotates them accordingly. This option is very powerful as it enables you to identify any logon event that was considered privileged by the operating system.

  • ANY – Returns all results, regardless of privilege level no filter is applied.