The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

General rule options

Prev Next

msg

In the msg rule option, you indicate the alert message. It is a simple text string that utilizes the \ as an escape character to indicate a discrete character such as a semi-colon.

Syntax:

msg: "<message text>";

When you create a Snort Custom Attack in the Custom Attack Editor, the Manager assigns the attack and rule name, which you cannot edit directly. The format of the name is as below:

Snort: <text entered for msg option> (sid: <sid value>)

The argument of the msg option features in the attack and rule name that the Manager assigns. Changing the msg argument or sid value and saving the rule will change the attack and rule name accordingly.

reference

In a rule, you can use the reference keyword to include references related to the corresponding attack traffic. For example, it could be the bugtraq or CVE id of known vulnerabilities. It could also be the address of a website that provides the details of the attack.

The following are the supported systems that you can specify in the reference option:

  • bugtraq

  • CVE

  • Trellix IPS ID

  • Arachnids

  • URL

Syntax:

reference:<id system>, id;

Examples:

reference: bugtraq, 514;

reference: url, www.microsoft.com/technet/security/bulletin/MS99-034.mspx;

You can view the references that are currently available in the Manager.

gid

gid stands for generator id and is not relevant in Trellix IPS. So, do not use them in your rules.

sid

sid stands for Snort rule ID. You must specify a unique sid for each Snort rule in the Manager. For Snort Custom Attacks that failed to import, the Manager assigns -1 as the sid.

Syntax:

sid:<sid value>;

rev

This enables you to identify any revisions of an existing rule. It is not a mandatory option, but Snort Custom Attacks without the rev option are converted with a warning. When you edit a Snort Custom Attack in the Manager, you can modify the rev value for your reference.

If you want to re-import a Snort Custom Attack with the same sid, then you can change the rev value and import it. The Manager overwrites the existing Snort Custom Attack with the one that you last imported.

Syntax:

rev:<revision integer>;

classtype

This is one of the options that you can use to categorize a Snort rule. In the Snort rules provided by Snort.org, the classtypes with the default priority are defined in the classification.config file. You can use these classtypes by importing the classification.config file into the Manager. Alternatively, you can define your own in a .config file and import it into the Manager. If you are defining your own classtype, then make sure you also assign a priority to the classtype.

Note

A rule must have a classtype or a priority.

Note

You can view the classification types that are currently available in the Manager.

Syntax for using a classtype in a rule is as follows. This assumes that the class name is available in the Manager database:

classtype: <class name>;

Syntax (for defining a classtype in a .conf file):

config classification: <class name>,<class description>,<default priority>

Example:

config classification: attempted-user,Attempted User Privilege Gain,1

priority

Using the priority option you can assign a severity to the rule. This overrides the default severity defined in the classtype.

The Manager assigns the severity for a Snort custom attack based on the following:

  • A priority 1 Snort attack definition is assigned a severity of High.

  • A priority 2 Snort attack definition is assigned a severity of Medium.

  • A priority of 3 or higher is assigned a severity of Low.

Syntax:

priority: <integer value>;