The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a Client Group on the NI CLI

Prev Next

Prerequisite: Make sure that you have set up the NI appliance and configured one or more required Client Profiles on it using the NI CLI. For more information, refer to the topic Create a Client Profile on the NI CLI.

Perform the following steps to create a Client Group on the NI CLI:

  1. Log into the NI CLI using a terminal window or SSH client:

    • Using the SSH protocol, log into the appliance with management interface's IP address or hostname.

      $ ssh npadmin@<NI appliance IP address>

    • Enter the password when prompted. The hostname > prompt is displayed after you have logged in.

  2. Enter privileged mode on the NI CLI

    npadmin@hostname> enable

  3. Enter the npadmin password, when prompted. The password can be 5 to 24 characters long.

    [sudo] password for npadmin: <password>

  4. Enter configuration mode

    npadmin@hostname# configure system

    The prompt changes to npadmin@hostname(config)# on the terminal indicating that configuration mode is enabled. You can now proceed with the Client Group configuration task.

  5. Type client-group at the terminal and press Enter.

    Client Group configuration options are displayed in the Group(s) page on the terminal.

    Note

    If you have already configured one or more Client Groups configured on the NI appliance, the prompt will display the names of all Client Groups under the Group(s) section in ascending numerical order starting with value 0.

    Note

    You can create up to 10 Client Groups on an NI appliance using its CLI.

    Group(s)            Page 1/1
    ----------------------------------------
    
     0) IPSGroup_SantaClara
     1) IPSGroup_SanJose
    
    ----------------------------------------
    
    A) Add Group
    #) Edit/Delete Group
    Q) Exit
    
    ----------------------------------------
    
    Enter your choice:
    
    
  6. To add a new Client Group, type A in the Enter your choice field and press Enter.

    Add new group page displayed with the following configuration options.

    Add new group.
    ----------------------------------------
    
    1. Name :
    2. Profile :
    3. Poll Interval(mins) :  30
    4. Flow WhiteList(count) :  0
    5. Metadata Engines :  []
    6. Home_Network(count) :  0
    7. PX Host(count) :  0
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    Enter your choice:
    
  7. Type 1 and press Enter to create a name for the Client Group being configured. Enter the name of the group in the Enter group name field and press Enter. The name given (i.e, IPS_Group in the example below) will now reflect in the Name section.

    Add new group.
    ----------------------------------------
    
    1. Name :  IPS_Group
    2. Profile :
    3. Poll Interval(mins) :  30
    4. Flow WhiteList(count) :  0
    5. Metadata Engines :  []
    6. Home_Network(count) :  0
    7. PX Host(count) :  0
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    Enter your choice:
    

    Note

    If you wish the edit the Client Group name, type 1 again in the Enter your choice field, and press Enter. Provide the new name and press Enter.

  8. Type 2 and press Enter to assign a Client Profile to the Client Group being configured.

    The Profile(s) page is displayed with the list of Client Profiles configured on the NI CLI.

    Profile(s):
    ----------------------------------------------
    1 )  IPS_Profile_SanJose
    2 )  IPS_Profile_SantaClara
    3 )  IPS_Profile
    
    C: Back to Prev Menu.
    
    Enter your choice:
    

    To specify a Client Profile, type the numeric value assigned to the profile and press Enter. If you wish to assign IPS_Profile (as shown the example above) to the group being configured, type 3 and press Enter. The Client Profile name will now reflect in the Profile field under the Add new group page.

    Add new group.
    ----------------------------------------
    
    1. Name :  IPS_Group
    2. Profile :  IPS_Profile
    3. Poll Interval(mins) :  30
    4. Flow WhiteList(count) :  0
    5. Metadata Engines :  []
    6. Home_Network(count) :  0
    7. PX Host(count) :  0
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    Enter your choice:
    

    Or, Enter C and then press Enter to go back to the previous Add new group page menu

  9. On Add new group page menu, type 3 and press Enter to set up the polling interval in minutes. This polling interval duration is used by both the Manager and Sensors to retrieve the configuration and filter parameters from the Client Profile assigned and apply the configuration or any changes made in the configuration to the alert data and flow data before exporting it to the NI appliance, when it is integrated with the Trellix IPS solution.

    1. Provide the Polling interval value in minutes. You can enter any number between 30 to 1440.

      Enter poll interval between 30 to 1440:38
      

      Note

      The default polling interval is set to 30 minutes.

    2. Once set, the value assigned will reflect in the Add group name page menu.

      Add new group.
      ----------------------------------------
      
      1. Name :  IPS_Group
      2. Profile :  IPS_Profile
      3. Poll Interval(mins) :  38
      4. Flow WhiteList(count) :  0
      5. Metadata Engines :  []
      6. Home_Network(count) :  0
      7. PX Host(count) :  0
      
      ----------------------------------------
      
      X. Save and Return
      C. Cancel and Return
      #. Select profile field
      Enter your choice:
      
  10. (Optional) Type 5 and press Enter to enable the metadata engine(s).

    Configure detection engines page is displayed on the terminal with the following options:

    Configure detection engines.
    ----------------------------------------
    
     1. Beaconing                      N
     2. Domain Generation Algorithm    N
     3. Data Exfiltration              N
    
    ----------------------------------------
    
    C. Cancel and Return
    X. Save and Return
    #. Toggle detection engine status
    
    ----------------------------------------
    
    Enter your choice:
    
    1. The metadata engines are disabled by default and shows N to reflect the disabled status. You may choose to enable any detection engine as per your investigation requirement.

    2. To enable a specific detection engine, type the numeric value assigned to that engine and press Enter. The status of the engine changes to Y to reflect the enabled mode. For example, in the engine configuration options presented above, you need to type 3 and press Enter to enable Data Exfiltration Engine that allows you to monitor alerts generated by this engine on the NI Web UI and identify any data extraction patterns or possible malicious data exfiltration attack over your network. Repeat the same procedure for any other detection engine you wish to enable.

    Note

    Entering the numeric value assigned to metadata engine already configured disables it, and its status changes to N to reflect the disabled status.

    To save and return to the Add new group page menu, type X and press Enter. Or, type C and press Enter to abort the changes made and return to the Add new group page menu.

    The names of the metadata engine(s) enabled reflect in the Add group name page menu.

    Add new group.
    ----------------------------------------
    
    1. Name :  IPS_Group
    2. Profile :  IPS_Profile
    3. Poll Interval(mins) :  38
    4. Flow WhiteList(count) :  0
    5. Metadata Engines :  ['dga', 'beaconing', 'data-exfill']
    6. Home_Network(count) :  0
    7. PX Host(count) :  0
    
    ----------------------------------------
    
    X. Save and Return
    C. Cancel and Return
    #. Select profile field
    Enter your choice:
    
  11. (Applicable only if you have any Packet Capture (PX) appliance deployed in your network and integrated with Trellix NI), type 7 and press Enter to add the PX host(s).

    The PX Host(s) page is displayed on the terminal.

    PX Host(s):
    
    
    ----------------------------------------
    
    A. Add px
    #. Delete px
    C. Cancel and return.
    X. Save and return.
    Enter your choice:
    
    1. To add a PX host to the Client Group, type A and press Enter.

      The Px(s) page opens on the terminal showing the list of IP addresses of the PX hosts connected to NI.

      Px(s)            Page 1/1
      ----------------------------------------------
      
      1 )  10.1.1.1
      2 )  10.1.1.2
      3 )  10.1.1.3
      
      ----------------------------------------
      C: Back to Prev Menu.
      
      Enter your choice:
      
    2. To specify a PX host, type the numeric value assigned to the host's IP address and press Enter. You are directed to the PX Host(s) page which now reflects PX host IP address chosen by you.

      PX Host(s):
      1) 10.1.1.1
      
      ----------------------------------------
      
      A. Add px
      #. Delete px
      C. Cancel and return.
      X. Save and return.
      Enter your choice:
      

      To save and return to the Add New Group page menu, type X and press Enter. Or, type C and press Enter to abort the changes made and return to the Add New Group page menu.

      The Add new group page opens on the terminal displaying the PX host count.

      Add new group.
      ----------------------------------------
      
      1. Name :  IPS_Group
      2. Profile :  IPS_Profile
      3. Poll Interval(mins) :  38
      4. Flow WhiteList(count) :  0
      5. Metadata Engines :  ['dga', 'beaconing', 'data-exfill']
      6. Home_Network(count) :  0
      7. PX Host(count) :  1
      
      ----------------------------------------
      
      X. Save and Return
      C. Cancel and Return
      #. Select profile field
      Enter your choice:

      Important

      If you have already added a PX host to a Client Group, the same PX host cannot be added to any other Client Group. As a result, the IP address of that PX host will no longer be available in thePx(s) page during the configuration of any other Client Group.

  12. Type X and press Enter to save the changes and finish the Client Group configuration task. In case you do not wish to proceed with the Client Group configuration changes, type C and press Enter which will cancel all the configurations made for the Group and redirects back to the Group(s) page.

    You would see the following message at the terminal confirming the addition of the Client Group:

    added group successfully
    Press enter to exit
    

    Press Enter to go back exit the Add new group page menu.

  13. The Group(s) page is displayed with the configured Client Group in the list:

    Group(s)            Page 1/1
    ----------------------------------------
    
     0) IPSGroup_SantaClara
     1) IPSGroup_SanJose
     2) IPS_Group
    ----------------------------------------
    
    A) Add Group
    #) Edit/Delete Group
    Q) Exit
    
    ----------------------------------------
    
    Enter your choice:
    
    
  14. Enter the numeric value assigned to the Client Group configured in the Enter your choice field and Press Enter. The group-specific details is displayed on the terminal

    Group:
    
    Token :  e4c567e18214df581214db8c62sb3n03
    ----------------------------------------
    
    1. Name :  IPS_Group
    2. Profile :  IPS_Profile
    3. Poll Interval(mins) :  38
    4. Flow WhiteList(count) :  0
    5. Metadata Engines :  ['dga', 'beaconing', 'data-exfill']
    6. Home Network(count)  :  0
    7. PX Host(count) :  1
    ----------------------------------------
    
    #. Edit group field
    D. Delete the group
    X. Save and Return
    C. Cancel and Return
    Enter your choice:
    

    Note down the authentication hash token of 32 bytes and the Client Group name which would be required at the time of configuring the Client Group on the Manager UI for successful integration of NI.