The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring IPS event notification delivery mode

Prev Next

You can use the Web UI or CLI to configure the delivery mode by which the Network Security appliance sends IPS event notifications:

  • About IPS event notification delivery mode

  • Configuring IPS event notification mode (Web UI)

  • Configuring IPS event notification mode (CLI)

About IPS event notification delivery mode

If IPS event notifications are configured (as described in Configuring IPS event notification delivery methods), the system uses one of the following modes to deliver the notifications:

  • instant—Send notification only when an IPS event is detected. This is the default value.

  • confirmation—Send notification only when an attack has been confirmed (either positive or negative).

  • dual—Send notifications both when an IPS event is detected and when an attack has been confirmed.

By default, the system is configured to use instant delivery mode, which is useful in an organization that archives notifications and then filters and analyzes the information later. When you first activate IPS features, we recommend that you use dual mode so that you see both detection and confirmation of IPS events. If your organization does not archive the volume of notifications generated in this mode, you can decrease the volume of notifications by using confirmation mode.

You can configure when IPS event notifications are sent by using either the Web UI or the CLI.

Configuring IPS event notification mode (web UI)

This topic describes how to use the Web UI to configure when IPS event notifications are sent for an IPS platform.

When you first activate IPS features, we recommend that you use dual delivery mode for IPS event notification instead of the default instant delivery mode. The dual mode enables you see both detection and confirmation of IPS events. For more information about all delivery modes, see IPS event notifications.

Prerequisites
Procedure

To configure when IPS event notifications are sent:

  1. Choose Settings > Notifications to display the current configuration of event notifications.

  2. In the Event Type column, select the IPS event notification the delivery mode.

    • instant—Send notification only when an IPS event is detected. This is the default value.

    • confirmation—Send notification only when an attack has been confirmed (either positive or negative).

    • dual—Send notifications both when an IPS event is detected and when an attack has been confirmed.

    When you first activate IPS features, we recommend that you use dual mode.

    scap_ips_settings_notifications_mode.png

Next step in setting up IPS

Go to Configuring notification of inline packet Inspection process state changes (CLI). You cannot configure this option from the Web UI.

Configuring IPS event notification mode (CLI)

This topic describes how to use the CLI to configure when IPS event notifications are sent for an IPS platform.

When you first activate IPS features, we recommend that you use dual delivery mode for IPS event notification instead of the default instant delivery mode. The dual mode enables you see both detection and confirmation of IPS events. For more information about all delivery modes, see IPS event notifications.

Prerequisites
Procedure

To configure when IPS event notifications are sent:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Configure the delivery mode.

    • instant—Send notification only when an IPS event is detected. This is the default value.

    • confirmation—Send notification only when an attack has been confirmed (either positive or negative).

    • dual—Send notifications both when an IPS event is detected and when an attack has been confirmed.

    When you first activate IPS features, we recommend that you use dual mode.

    hostname (config) # fenotify preferences ips dual
  3. Verify your changes.

    hostname (config) # show fenotify preferences
    Notification customized settings:
    IPS delivery mode: dual
    HTTP(s) notification using fenet proxy: yes
    Rsyslog notification Stripping off line feedback: yes
  4. Save your changes.

    hostname (config) # write memory
Next step in setting up IPS

Go to Configuring notification of inline packet inspection process state changes (CLI). You cannot configure this option from the Web UI.