Use SFTP to retrieve logs Published on Sep 12, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next Configure the Trellix Enterprise Security Manager - Enterprise Log Manager to allow SFTP access to retrieve logs.
You must have ELM SFTP Access rights.
Open an SFTP client such as WinSCP 5.11, Filezilla, CoreFTP LE, or FireFTP.
Connect to the Trellix Enterprise Security Manager - Enterprise Log Manager using its IP address and the configured SFTP port.
Note The date indicates when the system inserted the log to the Trellix Enterprise Security Manager - Enterprise Log Manager .
The files are presented in two ways: 1) by data source then data and 2) by date then data source.
Select the logs and transfer them. Specific steps to accomplish this vary based on the SFTP client you are using.
Important Maximum number of files for SFTP transfers is 20,000.
Was this article helpful?
Yes No
Related articles
Enterprise Security Manager > Enterprise Security Manager 11.6.x > ESM 11.6.x Product Guide > Finding threats > How log search works
Enterprise Security Manager > Enterprise Security Manager 11.7.x > ESM 11.7.x Product Guide > PG - ESM - Tuning McAfee ESM > Device configuration > Enterprise Log Manager (ELM) > Store logs on a Trellix Enterprise Log Manager (ELM)
Enterprise Security Manager > Enterprise Security Manager 11.6.x > ESM 11.6.x Product Guide > PG - ESM - Tuning McAfee ESM > Device configuration > Enterprise Log Manager (ELM) > Store logs on a Trellix Enterprise Log Manager (ELM)