The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert for Connection Limiting policies

Prev Next

You can define the threshold values while creating rules in a Connection Limiting policy. When the Sensor monitors a traffic and the connection exceeds the configured threshold value, the connection is limited and an alert is raised. You can set any of the following response actions:

  • Alert only

  • Alert and drop excess connection

  • Alert and deny excess connection

  • Alert and quarantine

There is only one reconnaissance alert defined for the Connection Limiting feature: Too Many TCP/UDP/ICMP Sessions. You can view the alert in Attack Log under the Analysis tab. Double-click the alert to view the alert details.

Scenario

Same host triggering the same rule:

In this scenario, no alert will be sent to the Attack Log during the alert timeout interval. So, when a traffic is sent to the Sensor, you can see the alert only after 5 minutes the first alert is triggered. This condition is not true for the Connection Limiting alerts for different hosts or different rules.

Note

By default the alert timeout interval is 5 minutes. You can edit the alert timeout from the reconnaissance policy editor.

Exceed connection count

Exceed Connection Count is displayed by the Connection Limiting alert when the response action is Alert Only.

Sensor sends out Connection Limiting alert as soon as the pre-defined threshold value is reached. So, the first alert always shows Exceed Connection Count as 1. If the traffic continues and triggers another alert after the alert timeout interval (with same connection limiting policy), then the Exceed Connection Count displayed in the next alert equals to the exceed connection count that the Sensor monitors between these two alert time intervals.

If the traffic does not continue long enough to reach the next alert time interval, another Connection Limiting alert will not be triggered. In this case, even if the connection exceeds the configured threshold value, the connection will not be limited.

Connection Limiting Host Entries Exhausted alert

The connection is limited based on the threshold defined but no alerts are sent.