The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deployment scenario for intermediate users

Prev Next

The pre-configured policies have an umbrella effect — you are protected from all the critical attacks defined in the policy. This enables you to get up and running quickly, but it also may protect you against attacks you do not care about. This would mean wasting the Sensor resources on things that are not relevant for your network. For example, if you have an entirely Solaris environment, you may not care if someone is initiating IIS attacks against the network, because these attacks are irrelevant to you. Some administrators prefer to see all network activity, including unsuccessful attacks, to get a complete picture of what is occurring on the network. Others want to reduce the "noise" generated by irrelevant attacks. Tuning your policies to delete attacks that do not apply to your environment reduces the amount of unimportant alerts generated by your Sensors.

To tune your deployment, you might do the following:

  • Try a more advanced deployment mode. If you were running in SPAN mode, you may choose to try another deployment mode, such as tap mode.

  • Take advantage of the Sensor's ability to apply multiple policies to multiple interfaces. Instead of applying a single policy to the entire Sensor, you may try applying different policies to dedicated interfaces of the Sensor. You can go a step further and segment your traffic into VLAN tags or CIDR blocks, create sub-interfaces, and apply policies to the Sensor's sub-interfaces.

  • Tune your policies. Pick the policy that best matches your needs and clone the policy (or create a policy from scratch). Then remove any irrelevant attacks, add any additional attacks, and configure appropriate response actions to respond to detected attacks.

  • Generate reports, view alerts, view the information presented in the Dashboard. Look at the data generated by the system to help you further tune your policies, and if necessary, implement more granular monitoring or delegation of monitoring activities to others.