The alert rate of a Manager/Central Manager is the number of alerts processed by the Manager per second. The alert rate mainly depends on the event rate in the Manager. The event rate of a Manager/Central Manager is the number of events processed by the Manager per second. An event can be defined as an action performed in the Sensor like an alert, packet log, ACL event, IPS event, performance monitoring, application identification, etc. The total number of events generated by the Sensors attached to a Manager depends on various parameters like type of traffic, amount of traffic, policies used, Sensor capacity, etc.
The following table details the test conditions when the Manager alert rate is 300 per second at an event rate of 375 per second:
Server Details | Sensor models | Composition of Traffic |
|---|---|---|
Windows 2022 based Manager server virtual machine 32GB RAM 8 x 2.2GHz CPU cores 500GB Hard Disk Drive 16GB allocated for JVM (by default) | NS-series Sensors Virtual IPS Sensors | Malware alert ranging between 20% to 80% and Signature ranging between 80% to 20% with Packet logging enabled |
Signature alert ranging between 40% to 60%, Malware alert ranging between 20% to 40%, Alert with GTI and DNS Lookup upto 20% with Packet logging enabled | ||
Linux based Manager server virtual machine 32GB RAM 8 x 2.4GHz CPU cores 500GB Hard Disk Drive 24GB allocated for JVM (by default) | Signature set attack only traffic with Packet logging enabled | |
Malware only traffic with Manager Block list, Trellix IPS Analysis, GTI File Reputation, and Gateway Anti-Malware engines enabled |
Note
The IPS alerts comprises up to 80% of the total events in the Trellix IPS.
Note
The alert rate and the event rate are higher in a Linux based Manager appliance when compared to a Windows or Linux based Manager virtual machines.
For example, consider an organization using the Trellix IPS solution. The network has four different subnets as follows:
Subnet | Policies used | Amount of traffic inspected | Average number of alerts generated per second |
|---|---|---|---|
Engineering | Default Testing | 300 Gbps | 200 |
Finance | Default Testing with Default Malware | 40 Gbps | 50 |
Sales | Default Prevention | 80 Gbps | 100 |
Human Resource | Default Detection | 30 Gbps | 75 |
Each of the above subnets is managed by a separate Manager.
In the above network, Finance, Sales, and Human Resource subnets have lower alert rate. So, the alerts are seen in the Attack Log page of the Manager in real time. But in the Engineering subnet, the alert is higher. These additional alerts are placed in a queue to be processed by the Manager and result in delays. When such delays accumulate over time, the Manager fails to fetch alerts in real time, and consequently, the Attack Log does not show up-to-date alerts. To achieve a higher alert rate in the Manager, you can upgrade to the Manager version 10.1.7.65 or higher, where the alert rate is 300 per second when the event rate is up to 375 per second.
If you observer higher alert rate in your environment regularly, do the following:
The Manager must be upgraded to software version 10.1.7.65 or higher.
Fine tune the IPS policies used.
Note
Trellix recommends you to avoid using the Default Testing policy. This policy includes all types of attacks and some of these attacks may not be relevant to your network. Instead, you can identify and disable such irrelevant attacks or use the Default Prevention policy.
Configure Alert Filters or Ignore Rules to avoid known traffic like the traffic from vulnerability scanners, testing servers, etc.
Configure Firewall Rules to skip scanning traffic from known source or destination IP addresses and vulnerability scanners.
Configure Auto Acknowledgment for low and informational severity attacks. This will save the Manager CPU cycles consumed for alert processing of source or destination IP addresses like DNS queries, GTI calls, etc.
Configure scheduled DB pruning to maintain only around 10 million alerts or 90 days of alerts as recommended in your enterprise network policy.
Install another Manager server and divide the Sensors between these Managers such that the alerts are not overloaded in an individual Manager.
If you are using a Central Manager to manage the Managers running version 10.1.7.65 or higher, the value of iv.core.nscm.alertSize attribute in the ems.properties file of the local Manager should be updated.
To edit the ems.properties file in the Manager, do the following:
Windows based Manager server
RDP to the Manager server.
Go to
<Manager_Install_Dir>\config\ems.propertiesNote
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.In the
ems.propertiesfile, locate the following:iv.core.nscm.alertSize=50
Edit the above line as follows:
iv.core.nscm.alertSize=500
Note
If you are having high alert rate in your Manager, set the
iv.core.nscm.alertSizeattribute value to 1500 for high alert synchronization between the Central Manager and the Manager.Save the changes.
Reboot the Manager server.
Linux based Manager server
Log in to the Manager shell.
Execute the
edit ems.propertiescommand.Note
The
editcommand will edit the file using vi-editor. Trellix recommends you to use vi_editor command to perform editing operations on the files.In the
ems.propertiesfile, locate the following:iv.core.nscm.alertSize=50
Edit the above line as follows:
iv.core.nscm.alertSize=500
Note
If you are having high alert rate in your Manager, set the
iv.core.nscm.alertSizeattribute value to 1500 for high alert synchronization between the Central Manager and the Manager.Save the changes.
Execute the
rebootcommand to restart the Manager server.