The Trellix IPS Manager manages the Virtual IPS Sensor instances launched in AWS. The Cluster is a group of Virtual IPS Sensors. The instances in a VPC are protected by the Virtual IPS Sensors assigned to that VPC. You can add multiple VPC groups to be protected within a Cluster. All the Virtual IPS Sensors in a cluster have the same policies, attack detection methods, rules, signature sets and software versions.
Before creating a launch configuration for auto scaling group, you have to first create a Cluster for auto scale in the IPS Manager. For more information on creating a cluster, see the section Create a Cluster.
.png)
When a signature set update is applied to a Cluster, all the member instances in that cluster are updated. When a Sensor is not updated in the cluster, the status is displayed as Failure for the cluster under Running Tasks. This happens when the Sensor is in inactive state during the update. Once the Sensor is active, the cluster has to be manually updated. To view the failed task, go to Manager → <Admin Domain Name> → Troubleshooting → Running Tasks.