The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations for rules converted with warnings

Prev Next

Some valid rules may convert with conversion result as Warning. The conversion result is displayed in the Validation Results column. By default, rules with Warning are set to Staged. There are two reasons why rules convert with a warning.

  • Rules for which there is an equivalent Trellix IPS signature in the Manager are converted with warnings. The Manager identifies such rules based on the CVE ID mentioned in the rule and the signature. You can click on an excluded attack and change its State to Published. You can specify your preference in the Custom Attack Editor so that, going forward, the duplicate Snort custom attacks are published in the corresponding policies by default. For information on how to set this preference, see the section Check for overlaps with Trellix IPS attacks.

  • Rules that do not have certain rule options are converted with a warning. However, based on your requirement, you can set such rules to Published state. It is recommended that you investigate such rules to check if they impact Sensor performance. If so, fix the rules before you publish them in the rule sets.