The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Supported platforms

Prev Next

This release of Logon Tracker module is supported on Endpoint Security (HX) server 5.3.0 and later with xAgent v35 and later running on Windows, Linux, and macOS. For a full list of supported OS versions refer to, Endpoint Security Agent documentation.

The Logon Tracker module is supported on Endpoint Security (HX) server 5.3.3 with xAgent v36 for the deployments that include Mac ARM Endpoints.

Note

To upgrade from previous versions of Logon, follow the instructions provided in Installing the Logon Tracker Module on Installing Logon Tracker module

By default, Logon Tracker is configured to retain logon events (event age limit) from the past 30 days. When performing incident response or investigating historical lateral movement older than 30 days, the event age limit must be increased or set to “unlimited”. See Filtering settings for more information.