The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Define the snort variables

Prev Next

You can define the snort variables in Trellix IPS and then use it in the rules.

Steps:

  1. Define the variables with the appropriate values in a file.

  2. Import the file into the Sensor.

    To define the variables in a file:

    1. Create a text file and change its file extension to .rules or .conf.

      Assume that you have named it variables.conf

    2. In the text file, define the variables as explained below

      • Use the var keyword to define a variable for a file path, IP addresses, and ports.

        For example, var RULE_PATH ../rules.

        In this example, RULE_PATH is the variable name and its value is the relative path to a folder named "rules".

      • Use the ipvar keyword to define a variable for IP addresses. Some examples are:

        • ipvar INSIDE_NETWORK [10.1.1.0/24, !10.1.1.22, 11.1.1.1, 12.1.1.0/24]

        • ipvar EXAMPLE1 [$INSIDE_NETWORK, !10.1.1.23]

        • ipvar EXAMPLE2 [$EXAMPLE1]

        • ipvar EXAMPLE3 [1.1.1.1, 2.2.2.0/24, ![2.2.2.2, 2.2.2.3]]

      • Use the portvar keyword to define the port numbers

        For example, portvar EXAMPLE_PORTS [100, 102, 150:160, !155]

        In this example, the value of EXAMPLE_PORTS is 100, 102, 150 through 160 except 155.

    3. Save the variables.conf file.

    To import the variables file into Sensor:

    1. In the Custom Attack Editor, from the Snort Format tab, click Snort Variables. Alternatively, to import select Other Actions → Import.

    2. Locate variables.conf and click Open.

      If you do not see the conf file at the location where you saved, check the Files of Type field in the Open dialog.

    3. Click Open.

      The Import Status may show zero for all the fields. Click OK.

    4. Select Snort Format to make sure the variables are imported with the values you specified in the variables.conf file.

    5. If a variable that you imported is already available in the database, it is assigned the value from the current import.