The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure the threshold mode

Prev Next

The threshold method provides administrators with a way to trigger alerts if a preconfigured traffic volume threshold is exceeded.

The key to successfully using thresholds is to have an understanding of the normal traffic levels on the network. In most cases, an external device such as a sniffer is used to baseline the network, and the initial levels are set according to that data. Once a baseline has been established, the administrator can enable the relevant threshold for an attack and configure each with values that make sense for a particular network.

Follow the tasks below to set threshold values for DoS attack definitions using Master Attack Repository. Note that the changes that you make through Master Attack Repository feature affects the corresponding attack definitions in all the IPS policies.

  1. Click the Policy tab.

  2. Select the root admin domain from the Domain drop-down list.

  3. Select Intrusion Prevention → Policy Types → IPS.

    The IPS page is displayed.

  4. Double-click on the row of Master Attack Repository column. The Attack Definitions page of the Master Attack Repository is displayed.

    GUID-0D60420D-4439-4845-A7B8-6CE0D65EB7A3-low.png
  5. Double-click on the row of the attack category DOS Threshold attack.

    The Settings tab for the attack is displayed.

  6. In the Threshold field set the attack threshold.

    For example, for the Threshold and Interval fields, select Set Explicitly and type 1000 and 1 respectively as values for these selections. Such a setting will enable an alert to be sent if a Sensor sees 1000 or more Inbound Link Utilization within a 1-second interval.

  7. In the Attack Definitions page, select the required DoS Threshold attack from the list.

    Press Shift key (for continuous selection) or press Ctrl key (for discontinuous selection) and then select the attacks.

    Setting threshold values

    Note

    The Threshold method can be configured only to send alerts; traffic meeting or exceeding the pre-defined thresholds cannot be blocked.

    The Threshold method is used mostly for troubleshooting. The administrator might want to be notified if bandwidth utilization goes above a pre-defined limit.

    In contrast to the threshold method, the learning-based method automatically establishes a baseline and if configured, can alert or block if that baseline is exceeded in such a way that it constitutes an attack.

  8. After you complete the customizing the attacks, click Update to update the changes to the attacks. Click Save and deploy the configuration changes to the corresponding Sensors.