The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to use the Ignore rules editor?

Prev Next

To manage Ignore Rules, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Ignore Rules. The Ignore Rules page is displayed.

From this page, you can perform the following tasks:

  • Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png to add Ignore Rules

  • Click GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png to copy Ignore Rules

  • To view or edit an ignore rule object double-click the row of the rule object

  • Click GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png to delete Ignore Rules

  • Click Save as CSV to save the Ignore Rules in CSV format.

The list on the Ignore Rules page displays the following information:

Field

Description

State

Specifies whether the state of the rule is Enabled or Disabled

Name

Specifies the name of the ignore rule.

Attack

Name — The name of the attack.

Direction — Displays whether the direction of the attack is Inbound or Outbound.

Scope

Specifies the resource to which the ignore rule is applied.

Attacker

Endpoint — Specifies the attacker endpoint IP address.

Port — Specifies the attacker port as TCP, UDP, TCP or UDP or Any.

Target

Endpoint — Specifies the target endpoint IP address.

Port — Specifies the target port as TCP, UDP, TCP or UDP or Any.

Last Updated

Time — Specifies the time when the Ignore Rule was last modified.

By — Displays the user who modified the Ignore rule

Comment

Displays any additional comment specified for the rule.

Search

Type your search criteria in the field to find the ignore rule with the matching elements.