The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Disable an attack definition

Prev Next

To disable an attack definition:

  1. For instructions up to this step, refer to the section Create and assign ignore rule objects.

  2. Select the source and destination IPs and ports in the corresponding fields.

    To disable an attack definition, select Any IPv4 address or Any IPv6 address and Any Port.

    Tip

    Since the Attack Name, Direction, Source, Source Port, Destination, and Destination Port are pre-populated with information about the alert, the only remaining steps to disable an attack definition are to choose to ignore a specific attack launched by all hosts, specify the source and destination ports, specify the scope of application of the exception, and click Save. Clicking Save will disable the attack definition.

  3. Select the Scope of the exception.

    Notice that the options for the scope of the exception will differ when you make choices as mentioned above. If you choose to disable the exception for a light-weight policy, select Interface and specify the exact interface. If you choose to disable the policy for a baseline policy, select Baseline Policy and specify the policy. If you choose to disable the exception for the entire domain, select Global.

    Note

    The default value will be set to Global, which will mean that the specific attack definition is disabled for the entire admin domain.

  4. Select the checkbox to acknowledge or delete the alerts that match the above mentioned settings, if necessary.

    It is not mandatory to select either of the options.

  5. Click Save.

    You will be prompted to run a configuration update for the changes to take effect.

  6. Click Yes.

    The Deploy Pending Changes window appears. Devices that lie within the purview of the scope of the exception are automatically selected. You can deselect this if you want to update the Sensor configuration later. Trellix recommends completing the Sensor configuration update.

  7. Click Deploy.

    The device configuration is updated and the attack definition is disabled as configured.