The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert rate

Prev Next

The alert rate of a Manager/Central Manager is the number of alerts processed by the Manager per second. The alert rate mainly depends on the event rate in the Manager. The event rate of a Manager/Central Manager is the number of events processed by the Manager per second. An event can be defined as an action performed in the Sensor like an alert, packet log, ACL event, IPS event, performance monitoring, application identification, etc. The total number of events generated by the Sensors attached to a Manager depends on various parameters like type of traffic, amount of traffic, policies used, Sensor capacity, etc.

The following table details the test conditions when the Manager alert rate is 300 per second at an event rate of 375 per second:

Server Details

Sensor models

Composition of Traffic

Windows 2022 based Manager server virtual machine

32GB RAM

8 x 2.2GHz CPU cores

500GB Hard Disk Drive

16GB allocated for JVM (by default)

NS-series Sensors

Virtual IPS Sensors

Malware alert ranging between 20% to 80% and Signature ranging between 80% to 20% with Packet logging enabled

Signature alert ranging between 40% to 60%, Malware alert ranging between 20% to 40%, Alert with GTI and DNS Lookup upto 20% with Packet logging enabled

Linux based Manager server virtual machine

32GB RAM

8 x 2.4GHz CPU cores

500GB Hard Disk Drive

24GB allocated for JVM (by default)

Signature set attack only traffic with Packet logging enabled

Malware only traffic with Manager Block list, Trellix IPS Analysis, GTI File Reputation, and Gateway Anti-Malware engines enabled

Note

The IPS alerts comprises up to 80% of the total events in the Trellix IPS.

Note

The alert rate and the event rate are higher in a Linux based Manager appliance when compared to a Windows or Linux based Manager virtual machines.

For example, consider an organization using the Trellix IPS solution. The network has four different subnets as follows:

Subnet

Policies used

Amount of traffic inspected

Average number of alerts generated per second

Engineering

Default Testing

300 Gbps

200

Finance

Default Testing with Default Malware

40 Gbps

50

Sales

Default Prevention

80 Gbps

100

Human Resource

Default Detection

30 Gbps

75

Each of the above subnets is managed by a separate Manager.

In the above network, Finance, Sales, and Human Resource subnets have lower alert rate. So, the alerts are seen in the Attack Log page of the Manager in real time. But in the Engineering subnet, the alert is higher. These additional alerts are placed in a queue to be processed by the Manager and result in delays. When such delays accumulate over time, the Manager fails to fetch alerts in real time, and consequently, the Attack Log does not show up-to-date alerts. To achieve a higher alert rate in the Manager, you can upgrade to the Manager version 10.1.7.65 or higher, where the alert rate is 300 per second when the event rate is up to 375 per second.

If you observer higher alert rate in your environment regularly, do the following:

  1. The Manager must be upgraded to software version 10.1.7.65 or higher.

  2. Fine tune the IPS policies used.

    Note

    Trellix recommends you to avoid using the Default Testing policy. This policy includes all types of attacks and some of these attacks may not be relevant to your network. Instead, you can identify and disable such irrelevant attacks or use the Default Prevention policy.

  3. Configure Alert Filters or Ignore Rules to avoid known traffic like the traffic from vulnerability scanners, testing servers, etc.

  4. Configure Firewall Rules to skip scanning traffic from known source or destination IP addresses and vulnerability scanners.

  5. Configure Auto Acknowledgment for low and informational severity attacks. This will save the Manager CPU cycles consumed for alert processing of source or destination IP addresses like DNS queries, GTI calls, etc.

  6. Configure scheduled DB pruning to maintain only around 10 million alerts or 90 days of alerts as recommended in your enterprise network policy.

  7. Install another Manager server and divide the Sensors between these Managers such that the alerts are not overloaded in an individual Manager.

If you are using a Central Manager to manage the Managers running version 10.1.7.65 or higher, the value of iv.core.nscm.alertSize attribute in the ems.properties file of the local Manager should be updated.

To edit the ems.properties file in the Manager, do the following:

Windows based Manager server

  1. RDP to the Manager server.

  2. Go to <Manager_Install_Dir>\config\ems.properties

    Note

    The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

  3. In the ems.properties file, locate the following:

    iv.core.nscm.alertSize=50
  4. Edit the above line as follows:

    iv.core.nscm.alertSize=500

    Note

    If you are having high alert rate in your Manager, set the iv.core.nscm.alertSize attribute value to 1500 for high alert synchronization between the Central Manager and the Manager.

  5. Save the changes.

  6. Reboot the Manager server.

Linux based Manager server

  1. Log in to the Manager shell.

  2. Execute the edit ems.properties command.

    Note

    The edit command will edit the file using vi-editor. Trellix recommends you to use vi_editor command to perform editing operations on the files.

  3. In the ems.properties file, locate the following:

    iv.core.nscm.alertSize=50
  4. Edit the above line as follows:

    iv.core.nscm.alertSize=500

    Note

    If you are having high alert rate in your Manager, set the iv.core.nscm.alertSize attribute value to 1500 for high alert synchronization between the Central Manager and the Manager.

  5. Save the changes.

  6. Execute the reboot command to restart the Manager server.