You can delete an individual custom IPS rule from the IPS rules database on your IPS-enabled platform. To delete a custom IPS rule, use the Custom Rules page. When you delete a custom IPS rule, the system removes the rule from the appliance IPS rules database. The database stores both standard, Trellix-provided IPS rules and any custom IPS rules that you create.
In the following example of the IPS Custom Rules page, the appliance IPS rules database contains four custom IPS rules.

If an IPS policy that includes a deleted rule is already active on a monitoring interface, the rule remains in effect on that interface until you click the Delete (red trash can) icon and confirm the change.
Prerequisites
Logged in to the Web UI of the IPS-enabled platform as Operator or Admin.
An IPS rules database on your appliance contains one or more custom IPS rules.
Procedure
Choose IPS > Custom Rules.
The page lists the custom IPS rules in the appliance IPS rules database.
Locate the custom IPS rule you want to delete.

Click the Delete (red trash can) icon. A dialog box prompts you to confirm the changes.
Click OK.
The rule is removed from the database of IPS rules, and the IPS-enabled rules engine re-evaluates active IPS policies against the updated database of IPS rules. A message similar to the following appears:

Close the green message bar.