Trellix Endpoint Security (ENS) for LinuxHost Intrusion Prevention now supports both allowed and blocked traffic logging.
When Host Intrusion Prevention allowed traffic logging is enabled, the details of all allowed traffic are logged in syslog. By default this option is disabled. When Host Intrusion Prevention blocked traffic logging is enabled, the details of all traffic blocked are logged in syslog. By default this option is enabled.
For managed systems, you can enable logging activity using the Tuning Options in the Trellix Endpoint Security (ENS) for Linux Host Intrusion Prevention (Options) policy.
For standalone systems, you can configure log settings using command line.