Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
Press CTRL+K to open search
Configure Sensor alert logging for threat feeds as per IoC types
Alert detection and logging by Sensors for configured threat feeds differs by the imported IoC types that you want to use for threat detection and response.
If you have already configured the syslog server for firewall rules logging at the Sensor level, you can use the same server for detection and logging of these IoC types. For more information, see Enable syslog forwarding for Firewall at Sensor level.
If you do not have a target syslog server configured for firewall rules logging -
Configure a syslog server which the Sensors will be using to send IoC logging details. For more information, see Enable rule match notification.
Go to the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Logging → Firewall Access Logging page and select the configured server enable syslog forwarding for the required Sensors. For more information, seeEnable syslog forwarding for Firewall at Sensor level.
Note
In scenarios where the same IPv4/IPv6 endpoint or CIDR is configured in both a firewall policy (ACL) and as an active IoC in a threat intelligence feed, the IoC block action takes precedence over the Firewall Policy (ACL) block action. The prioritization of IoC block action is applicable even if the firewall policy was configured first.
Domains, URLs
Go to the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Inspection Options page and add an inspection options policy, or update an existing policy.
On the Traffic Inspection tab, under Miscellaneous, enable Layer 7 Data Collection in the required direction.
Configure the fields URL Reputation Analysis and Minimal URL Risk on the GTI Reputation Services tab.
Select the required Sensor(s) which you need to assign the policy to for the detection of these IoC types.
Go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware page and create an Advanced Malware policy, or edit an existing one.
Under the File Scanning Options, update the File Type, File Size for the Threat Feed/ Local Block List Malware Engine, and configure Action Thresholds to determine Sensor response to this IoC type.