The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create exceptions

Prev Next

As a network security administrator, you may sometimes notice a spike in alerts in the Attack Log from one host. Such high incidence of alerts can be caused by several factors which the IPS considers suspicious. You can either choose to act on every alert or provide a time frame during which the host issue can be resolved. During this period, you can choose to stop receiving alerts in the Attack Log and focus on other alerts.

In order to stop receiving such alerts temporarily, the Manager enables you with an option to create an alert exception that prevents such alerts from appearing in the Attack Log. An alert exception is a rule in the Manager that prevents specific alerts from showing up in the Attack Log, by automatically acknowledging similar alerts. Note that since you are only choosing to acknowledge the alerts automatically, the IPS process packets continues to generate alerts. IPS also continues to carry out response actions such as blocking, sending a TCP reset, etc. if any of these are enabled.

Note

Before you create an exception for any alert, it is important you make sure that the host in consideration will not be a potential threat. In most real-world situations, the host is usually an infected internal server or client which will not launch a full-scale attack. It is imperative to determine all factors that necessitate creation of an alert exception.