The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up Trellix Enterprise Security Manager - Event Receiver data archiving

Prev Next

Configure the receiver to forward a backup of the raw data to your storage device for long-term storage.

  • Port 445 must be opened on the system with the CIFS share to enable a CIFS share connection.

  • Port 135 must be opened on the system with the SMB share to enable an SMB connection.

  1. From the Trellix ESM dashboard, click and select More Settings .

  2. From the Trellix ESM dashboard, click and select More Settings .

  3. Click Receiver ConfigurationData Archival.

  4. Select a share type and enter the connection configuration information.

    • SMB/CIFS

      • Share type — Sets the share type to SMB or CIFS.

      • IP address — IP address of the share.

      • Share Name — Label applied to the share.

      • Path — Subdirectory on the share where the archived data must be stored (for example, TMP/Storage). If storage is in the root directory of the share, no path is needed.

      • User Name and Password — Credentials needed to connect to the share. Do not use commas in the password when connecting to an SMB/CIFS share.

    • NFS

      • IP address — IP address of the share.

      • Mount Point — Name of the mount point on the share.

      • Path — Subdirectory on the share where the archived data must be stored (for example, TMP/Storage). If storage is in the root directory of the share, no path is needed.

    • Syslog Forwarding

      • IP address — IP address of the share.

      • Port — Port used to archive data.