This section lists some important notes related to managing custom attacks in the Central Manager.
- You can create custom attack definitions for a Manager in the Central Manager. When you configure the Manager in the Central Manager the custom attack definitions are published to the Manager.
- You can create or edit custom attack definitions in a Manager.
- All custom attacks sent from the Central Manager to the Manager as part of synchronization are automatically saved in the Manager database and also published in the relevant policies.
- In a Manager, when an attack matching the custom attack definition is detected, you can view the alert in the Attack Log page of the Manager and Central Manager.
- In the Custom Attack Editor of the Manager, you cannot modify or delete any custom attack that was sent from the Central Manager. You cannot change the State of the Central Manager attack definitions in the Manager.
- When you synchronize the Central Manager with the constituent Managers, only the custom attacks with State as Published are sent to the Managers.
- If you remove a Manager from the Central Manager, all custom attacks sent from the Central Manager to the Manager are removed from the Manager database. To remove these attacks from the corresponding Sensors as well, you need to do a configuration update.
- Recall the custom attack capacity per Sensor type:
- You can use up to 4500 Trellix IPS Custom Attacks and 5000 Snort Custom Attacks per M-series and NS-series Sensor.
Factor this in when you send custom attacks from the Central Manager to the corresponding Managers.