The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring Snort engine at a global level

Prev Next

To configure the appropriate snort engine at a global level, perform the following steps:

  1. Go to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings.

    The default engine selected is the Trellix IPS Snort engine.

  2. To select the snort engine, click the Snort Rule Engine dropdown and select the Suricata Snort.

    A pop-up appears asking you to confirm your changes and informing you that a reboot will be necessary for the change to take effect.

    GUID-15BE91D4-0E76-480C-A9F2-1BA32F5AE94C-low.png
  3. Click OK and then click Save at the bottom of the page.

  4. Reboot the Sensors which require this change.

    After the reboot, the Advanced Device Settings page of the Sensor displays Suricata Snort.