You can use the Policy Editor to customize the Snort attacks like you would customize any other Trellix IPS attack. If you make any configuration changes to an attack, you should update the Sensor of the changes for them to take effect.
Note
By default, when you save a Snort attack to the database, Enable Attack and Enable Alert are enabled. All other configurations including blocking and packet logging are disabled.