The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Forward alerts to an SNMP server

Prev Next

You can configure the SNMP server to which alert information for Sensor or NTBA Appliance is to be sent.

You can configure more than one SNMP server. You can configure the SNMP servers for each admin domain separately. The SNMP server configured for a root admin domain can be different from the SNMP server configured for its child domains. When the Children and the Current checkboxes are selected while configuring an SNMP server for the root admin domain, the SNMP server configured for the child domain will forward notifications to both the parent and child domain SNMP servers. When the Children checkbox is not selected in the root admin domain, then the child domain will use only the SNMP server configured for that domain to forward notifications. The SNMP Servers list on the SNMP tab displays the SNMP servers you have configured.

Task

  1. Select Manager → <Admin Domain Name> → Setup → Notification → IPS Events/NTBA Events → SNMP.
    The SNMP tab is displayed where Enable SNMP Notification option and the configured SNMP Servers list is displayed.
  2. Select Yes against Enable SNMP Notification and click Save.
  3. Click .
    The SNMP page is displayed.


  4. Specify your options in the appropriate fields.
    Field Description
    Admin Domains Specify whether this applies to the child domains as well.
    IP Address IP address of the target SNMP server. This can be an IPv4 or IPv6 address.
    Target Port SNMP listening port of the target server
    SNMP Version The version of SNMP running on your target SNMP server. Version options are 1, 2c, Both 1 and 2c, and 3.
    Community String Enter an SNMP community string to protect your Trellix IPS data. SNMP community strings authenticate access to Management Information Base (MIB) objects and functions as embedded passwords.
    Send Notification If By attack for Sensor and the attack definition has this notification option explicitly enabled for IPS — Forwards attacks that match customized policy notification settings, which you must set when editing attack responses within the Policy Editor.

    By Alert Filter for Sensor and the following notification filter is matched for NTBA — Sends notification for all, or based on the severity of alerts:

    • Severity Informational above — Includes all alerts
    • Severity Low and above — Includes low, medium, and high severity alerts
    • Severity Medium and above — Includes both medium, and high severity alerts
    • Severity High — Includes only high severity alerts
    The following fields appear only when SNMP Version 3 is selected.
    User Name User name for authentication
    Authoritative Engine ID (Hex Values) The authoritative (security) engine ID used for SNMP version 3 REQUEST messages by primary Manager.

    The hex value of the Authoritative Engine ID should have only even pairs (For example, you can have hex value of 4 pairs like 00-1B-3F-2C).

    Note

    MAC address can also be used as Authoritative Engine ID.

    Authoritative Peer Engine ID (Hex Values):

    Note

    The Authoritative Peer Engine ID field is available while configuring SNMP version 3 only after successful creation of an MDR pair.

    The authoritative (security) engine ID used for SNMP version 3 REQUEST messages by secondary Manager.

    Note

    The Authoritative (security) engine ID for any Manager is unique. At any point of time, the Authoritative Engine ID of the Manager is static irrespective of Manager status in case of an MDR pair. That is, when MDR switchover occurs, the authoritative engine ID of the Manager will not change with the status of the Manager. Hence, the alerts generated from the Primary and Secondary Manager will have their respective authoritative engine IDs.

    Note

    After successful deletion of an MDR pair, the Authoritative Engine IDs are retained by the respective Managers.

    Authentication Level This specifies the authentication level and has the following categories:
    • No Authorization, No Privileges — Uses User name match for authentication
    • Authorization, No Privileges — Provides authentication based on the MD5 or SHA algorithms
    • Authorization and Privileges — Provides authentication based on the MD5 or SHA algorithms. It also provides encryption in addition to authentication based on the DES or AES standards.
    Customize Community Enter an SNMP community string to protect your Trellix IPS data. SNMP community strings authenticate access to Management Information Base (MIB) objects and functions as embedded passwords.
    The following fields appear only when Authorization, No Privileges is selected as Authentication Level:
    Authentication Type The authentication protocol (MD5 or SHA) used for authenticating SNMP version 3 messages
    Authentication Password The authentication pass phrase used for authenticating SNMP version 3 messages
    The following fields appear only when Authorization and Privileges is selected as Authentication Level:
    Authentication Type The authentication protocol (MD5 or SHA) used for authenticating SNMP version 3 messages
    Authentication Password The authentication pass phrase used for authenticating SNMP version 3 messages
    Encryption Type The privacy protocol (AES or DES) used for encrypting SNMP version 3 messages
    Privacy Password The privacy pass phrase used for encrypting SNMP version 3 messages
  5. Click Save.
    The SNMP server is added to the SNMP Servers page.

    Note

    Do not use a broadcast IP address (that is, 255.255.255.255) as the target SNMP server for forwarding alerts.