The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Use SFTP to retrieve logs

Prev Next

Configure the Trellix Enterprise Security Manager - Enterprise Log Manager to allow SFTP access to retrieve logs.

You must have ELM SFTP Access rights.

  1. Open an SFTP client such as WinSCP 5.11, Filezilla, CoreFTP LE, or FireFTP.

  2. Connect to the Trellix Enterprise Security Manager - Enterprise Log Manager using its IP address and the configured SFTP port.

    Note

    The date indicates when the system inserted the log to the Trellix Enterprise Security Manager - Enterprise Log Manager.

    The files are presented in two ways: 1) by data source then data and 2) by date then data source.

  3. Select the logs and transfer them. Specific steps to accomplish this vary based on the SFTP client you are using.

    Important

    Maximum number of files for SFTP transfers is 20,000.