The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploy pending changes to the Suricata Sensor

Prev Next

If you change configurations or policies in the Manager, you must update the Sensors in your deployment for the changes to take effect.

Follow these steps to deploy changes to the Suricata Sensor in the admin domain.

Tip

You can monitor the status of the suricata configuration deployment on the Background Tasks page.

  1. Go to Devices → <Admin Domain Name> → Global → Device Manager. The Device Manager page is displayed.

  2. Click Sensors tab. Select the required Suricata Sensor from the list.

  3. Select Sync. The Sync: <Device Name> window is displayed.

    Note

    The Manager allows you to deploy pending changes to multiple Sensors simultaneously. When you select Sensors in the stack for deployment, the Bulk Sync window displays and selects all check boxes by default.

  4. Select the Suricata Config and click Sync.

  5. A Deployment Details dialog box is displayed to provide the status of the deployment.

View device details in the Manager

You can view the synchronization status in the Suricata Config Sync section. It can be accessed from Devices → <Admin Domain Name> → Global → Device Manager page and Devices → <Admin Domain Name> → Devices → <Device Name> → Summary. For Sensors in stack, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <sensor_stack_ID> → Summary.

Suricata Config Sync displays Status and Last Sync details.

  • Status column: The following status is displayed:

    Status

    Description

    Synchronized

    Indicates that no pending changes are required.

    Sync in progress

    Indicates when the deployment is in progress.

    Sync required

    Indicates if any pending changes are required.

    ---

    Indicates that there is no trust established between the Sensor and the Manager.

    Failed

    Indicates that pending changes have failed. You can click on info icon to view the failure details.

  • Last Sync column: It displays the timestamp of the last synchronization in MMM DD YYYY HH:MM:SS format. Example: Mar 04 2026 00:39:45

The Protections column displays whether a ruleset is present on the Sensor. This column also displays the ruleset version, if available. It can be accessed from Devices → <Admin Domain Name> → Global → Device Manager page and Devices → <Admin Domain Name> → Devices → <Device Name> → Summary. For Sensors in stack, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <sensor_stack_ID> → Summary.