The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up database audit trails

Prev Next

Set up an audit trail to track access and changes made to the database or to tables associated with specific database events. The Trellix ESM compliance report lists audit trails associated with each event.

To generate audit trail events, you must add:

  • Data Access rules

  • Privileged User Audit Trails report

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png and select Policy Editor.

  2. In the Rule Types pane, select DEMData Access.

  3. Highlight DEM - Template Rule - Trusted Use Access From IP Range.

  4. Click EditCopy, then click EditPaste.

  5. Change the name and properties of the new rule.

    1. Highlight the rule, then select EditModify.

    2. Name the rule, then type the user name.

    3. Select the Untrusted action type, then click OK.

  6. Click the Rollout icon GUID-A5690870-A648-4CC7-B1B1-F092A03B5C3B-low.png.

  7. Set up the report:

    1. On System Properties, click ReportsAdd.

    2. Fill in sections 1–3, and 6.

    3. In section 4, select Report PDF or Report HTML

    4. In section 5, select ComplianceSOXPrivileged User Audit Trails (Database).

    5. Click Save.

  8. To generate the report, click Run Now.