Events of this type include those alerting on activities associated with instant messaging (IM), internet relay chat (IRC), and peer-to-peer programs (P2P). Some security policies forbid such traffic on their network; for example, within a corporate common operation environment (COE); others may allow them to various degrees. Universities, for example, typically have a totally open policy for running these applications. Trellix IPS provides two means to tune out such events if your policies deem these events uninteresting. First, you can define a customized policy in which these events are disabled. In doing so, the Sensor will not even look for these events in the traffic stream to which the policy is applied. If these events are of interest for most of the hosts except a few, creating ignore rules to suppress alerts for the few hosts is an alternative approach.
Correct identification — significance subject to usage policy
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?