The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Editing a custom IPS rule (Web UI)

Prev Next

To edit a custom IPS rule in the IPS rules database on your appliance, use the Custom Rules page. When you edit a custom IPS rule, the system saves the updated rule to the appliance IPS rules database. The database stores both standard, Trellix-provided IPS rules and any custom IPS rules that you create.

In the following example of the IPS Custom Rules page, the appliance IPS rules database contains four custom IPS rules.

scap_ips_custom_rules_four_existing.png

If an IPS policy that includes a changed rule is already active on a monitoring interface, the rule change does not go into effect on that interface until you click and confirm Apply Rules.

Prerequisites
  • You are logged in to the Web UI as Operator or Admin.

  • The IPS rules database contains one or more custom IPS rules.

Procedure

To edit a custom IPS rule in the appliance database:

  1. Choose IPS Custom Rules.

    The page lists the custom IPS rules in the appliance IPS rules database.

  2. Locate the custom IPS rule you want to edit.

  3. Click the Edit (blue pencil) icon.

    scap_ips_custom_rules_edit_one.png

  4. Edit the rule definition in the text box. See Syntax for custom IPS rules on .

  5. Click Save.

    scap_ips_custom_rules_save_one.png

    • Your changes are saved to the database of IPS rules, and the following message appears:

      scap_ips_custom_rules_msg_edit_succeeded.png

    • If the edited rule contains a syntax error, you must edit the rule again to correct the error before you can save the changes to the database of IPS rules.

      scap_ips_custom_rules_msg_syntax_error.png

  6. Close the green message bar.

  7. When you are ready to apply the updated custom IPS rules, click Apply Rules.

    scap_ips_custom_rules_button_Apply_Rules.png

    Note

    Trellix recommends that you click Apply Rules immediately after the updaated rule has been successfully saved to the database.

  8. Click OK.

    The IPS-enabled rules engine re-evaluates active IPS policies against the updated database of IPS rules, and the following message appears:

    scap_ips_custom_rules_msg_apply_succeeded.png

  9. Close the green message box.