The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up event forwarding filters

Prev Next

Limit the event data forwarded to a syslog server on Trellix ESM.

Verify you have permission to access devices in the filter.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select Trellix ESM and click Settings.png.

  3. Click Event Forwarding.

  4. Click Add, then click Event Filters.

  5. Fill in the filter fields:

    Note

    Comma separated lists should not have space characters.

    Device:

    • Click GUID-C4056A30-9E8D-4DC5-832C-5E1D6B4C9461-low.png and select one or more device.

    Destination or Source IP:

    • Enter a single IP, comma separated list, or CIDR range of IP addresses (192.168.0.0/16).

    Destination Port:

    • Enter a single port or comma separated list.

    Protocol:

    • Enter a Single protocol or comma separated list.

    • Values can be protocol ID or String.

    Device Type:

    • Click GUID-C4056A30-9E8D-4DC5-832C-5E1D6B4C9461-low.png and select one or more device type.

    Normalized ID:

    • Click GUID-C4056A30-9E8D-4DC5-832C-5E1D6B4C9461-low.png select one or more Norm ID.

    Severity:

    • Select Greater than or equal to.

    • Enter a severity number between 0 and 100.