The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About alert policy exceptions

Prev Next

An alert policy exception enables you to override the actions defined alert rules. You can configure an alert policy exception for one or more alert rules or for all alert rules, and the exception policy can be limited to specified portions of the traffic that match the alert rules.

  • Attack category—To configure an exception for alert rules that belong to the same attack category, you specify one of the predefined category names: Infection-Match, Domain-Match, Malware-Callback, Riskware, IPS, Reconnaissance, or Local-Signature.

    Note

    If you instead specify "all" rules, a rule name, or a single rule, the policy exception is limited to rules in the predefined attack categories.

  • Signature name—To configure an exception for alert rules that address aspects of the same network vulnerability, you specify the signature name for that vulnerability.

  • Signature ID—To configure an alert policy exception for a single alert rule, you specify the eight-digit signature ID for that rule.

The scope of an alert policy exception can be further limited to a specified traffic flow:

  • Traffic through one or all monitoring port pairs or the management interface

  • Traffic through a specific source host IP address or subnet

  • Traffic through a specific destination IP address or subnet

Traffic that matches an alert policy exception is handled as specified by the policy override:

  • Force or disable blocking of traffic that matches the exception policy.

  • Suppress alert notifications and event logging for traffic that matches the exception policy, or enforce suppression combined with forced blocking.

  • Honor the action defined in the matched signatures.