The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Compilation of signature set based on priority attribute

Prev Next

Previously, when signature sets were pushed to the Sensors, the Manager used to push complete set of attack definitions in the Active Manager Signature Set to the Sensors. The older Sensor models having limited Sensor resources failed to accommodate the complete signature set. This resulted in signature set push failure. With this release, the Manager dynamically compiles signature set based on the priority attribute and pushes signatures based on the signature set attack priorities configured for the Sensor model. The attack definitions in a signature set are categorized as high, medium, and low using the priority attribute to optimize Sensor resources.

To configure the coverage of signature set for the Sensors, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Attack Compilation. On selecting Signature Set Attack, the Signature Set Attack Priorities option appears where you can configure the signature set to be pushed to the Sensors.

Note

Previously, the Attack Compilation page was available at Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Attack Compilation. Starting from this release, the Attack Compilation page is available at Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Attack Compilation.

The available signature set attack priorities are as follows:

  • All: Includes the full set of signatures, which comprises of high, medium, and low priority signature set attacks.
  • High and Medium only: Includes the partial signature set, which comprises of high and medium priority signature set attacks only.
  • High only: Includes smaller signature set, which comprises of high priority signature set attacks only.

To view the priority of an attack definition in the signature set, go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS . Double-click on any policy, the Attack Definition tab opens. The Priority column displays the predefined priority of an attack definition in the signature set. By default, the priority column is hidden.

Note

If you are running older software versions of NS-series, Virtual IPS, or M-series, Trellix recommends you upgrade the Sensors to the latest NS-series or Virtual IPS Sensor software versions.