The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deleting a custom IPS rule (Web UI)

Prev Next

You can delete an individual custom IPS rule from the IPS rules database on your IPS-enabled platform. To delete a custom IPS rule, use the Custom Rules page. When you delete a custom IPS rule, the system removes the rule from the appliance IPS rules database. The database stores both standard, Trellix-provided IPS rules and any custom IPS rules that you create.

In the following example of the IPS Custom Rules page, the appliance IPS rules database contains four custom IPS rules.

scap_ips_custom_rules_four_existing_delete_one.png

If an IPS policy that includes a deleted rule is already active on a monitoring interface, the rule remains in effect on that interface until you click the Delete (red trash can) icon and confirm the change.

Prerequisites
  • Logged in to the Web UI of the IPS-enabled platform as Operator or Admin.

  • An IPS rules database on your appliance contains one or more custom IPS rules.

Procedure
To delete a custom IPS rule from the appliance database:
  1. Choose IPS > Custom Rules.

    The page lists the custom IPS rules in the appliance IPS rules database.

  2. Locate the custom IPS rule you want to delete.

    scap_ips_custom_rules_delete_one.png
  3. Click the Delete (red trash can) icon. A dialog box prompts you to confirm the changes.

  4. Click OK.

    The rule is removed from the database of IPS rules, and the IPS-enabled rules engine re-evaluates active IPS policies against the updated database of IPS rules. A message similar to the following appears:

    scap_ips_custom_rules_msg_delete_succeeded.png
  5. Close the green message bar.