The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Import snort rules through a rules file

Prev Next

Before you begin

Make sure of the following before you begin importing a rules file:

  • All the variables, classifications, and references used in the rules are either defined in the rules files up front or already available in the Manager.
  • Just like a conf file, a rules file too can call other files. So, make sure the files called by a rules file are in place.

You can import rules directly from a rules file without a conf file. This section provides the steps for importing Snort rules into the Manager using a rules file.

Task

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.


  2. In the Custom Attack Editor of the Snort Format tab, click Other Actions → Import .


  3. Navigate to the .rules file to be imported.
  4. Click Open.
    All the rules are imported into the Manager and the valid ones are converted to Import snort rules through a conf file's format. There could be some rules that were successfully converted to Import snort rules through a conf file's format, some converted with warnings, and some that failed to convert.
  5. Select a Protection Category value.
    New Signature window


  6. Click Import.
  7. You can refer to the section Managing Snort rules to:
    • View the details of the imported Snort rules
    • Know which rules converted successfully, which converted with warnings, and which failed to convert