The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

DoS troubleshooting

Prev Next

This section lists issues related to DoS alerts.

Applicable to Sensor models: NS-series

Problem scenario

DoS alerts raised in Trellix IPS Manager.

Data/Information Collection

  1. Execute show dospreventionprofile <dos-measure-name> <inbound/outbound> in the Sensor.

  2. Trace the Sensor files.

Troubleshooting Steps

  1. Check for the source IP of the profile learning each of the packet types. Execute the following commands:

    • show dospreventionprofile tcp-syn inbound/outbound

    • show dospreventionprofile tcp-syn-ack inbound/outbound

    • show dospreventionprofile tcp-rst inbound/outbound

    • show dospreventionprofile udp inbound/outbound

    • show dospreventionprofile icmp-echo inbound/outbound

    • show dospreventionprofile icmp-echo-reply inbound/outbound

    • show dospreventionprofile icmp-non-echo-echoreply inbound/outbound

    • show dospreventionprofile ip-fragment inbound/outbound

    • show dospreventionprofile non-tcp-udp-icmp inbound/outbound

    Check the bins for long-term average traffic rate and short-term average traffic rate values. An alert is raised when the short-term traffic rate is higher than the long-term traffic rate.

    GUID-25397947-7135-4C09-8D06-9045E8A2D3EC-low.png
  2. Check bins that are blocked. A sample of the source IP profile during the detection stage which indicates the blocked bins is shown in the figure.

    GUID-93E22BB7-5BCD-40AD-B1D5-7039EA034675-low.png
  3. If many DoS alerts are raised frequently for a particular IP, it could be false positive. The reason could be due to the profile of that IP not studied properly.

  4. For volume related alerts (for example, if the inbound UDP volume is too high), check if the IP is missing in the alert details. To check the alert details, navigate to Analysis → <Admin Domain Name> → Attack Log and select the alert by clicking on it twice.

    GUID-03C60661-B8F4-4EC0-AE69-09754C9408A7-low.png

Solution

Rebuild the DoS profile to resolve the issue. To rebuild the DoS profile, perform the following steps:

  1. Click Devices → <Domain Name> → Devices → <Device Name> → Troubleshooting → Denial of Service → Data Management.

  2. In the DoS Profile Learning section, select Rebuild the DoS Profiles.

  3. Click Update.