The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Client Group Association tab

Prev Next

The Client Group Association tab allows you to enable association of any Client Group configured in the Manager at the domain level or device level. This tab is available in the following two places in the Manager:

  • The Devices → <Admin Domain Name> → Global → IPS Device Settings → NI Integration → Client Group Association tab helps in enabling the association of any Client Group for the admin domain as well as child domains. If you enable the NI integration at an admin domain level, all child domains and the Sensors attached to these domains inherit this settings. However, you can configure any child domain with a different Client Group as per your network requirement. Consequently, the Sensors attached to that domain will inherit the same settings, unless you opt for enabling the association of a separate Client Group with different configurations for any specific Sensor within that domain.

  • The Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → NI Integration → Client Group Association tab helps in enabling the association of any Client Group per Sensor basis within any domain, thus allowing further customization of NI integration settings.

    For example, assume that you have enabled the association of Client Group A for a child parent domain X which has Sensor 1, Sensor 2 and Sensor 3 attached to it. In Client Group A, you have enabled L7 metadata configuration for both HTTP and HTTPS protocols. Once the Client Group A is associated with X domain, all the three Sensors will inherit this settings. However, you wish to analyze only HTTPS protocol specific metadata in the netflows sent by Sensor 2 on the NI. In such a case, you can configure another Client Group with the desired l7 metadata configuration on the NI CLI and perform the configuration and association of that Client Group for Sensor 2 only in the Manager.

Note

Configuring a Client Group in Manager is mandatory prior to its association either at domain level or device level. If you have not configured it using the Client Group Configuration tab at the Global level, you can do it via the Client Group Association tabs available at both Global and Device levels.