The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing Snort rules for the Suricata Snort engine

Prev Next

Steps:

  1. Go to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings. The default engine selected is Trellix IPS Snort.

  2. To select the snort engine, click the Snort Rule Engine drop-down and select the Suricata Snort.

    A pop-up appears asking you to confirm your changes and informing you that a reboot will be necessary for the change to take effect.

    GUID-15BE91D4-0E76-480C-A9F2-1BA32F5AE94C-low.png
  3. Click OK and then click Save at the bottom of the page.

  4. Reboot the Sensors which require this change. Go to Devices → <Admin Domain Name> → Devices. Select the device to reboot. Go to Maintenance → Reboot. Click Reboot Now

    GUID-1654DAEF-C612-4568-92C4-5CF989E6EA0E-low.png

    After the reboot, the Advanced Device Settings page of the Sensor displays Suricata Snort.

  5. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click the Custom Attacks button (bottom left corner).

  6. In the Custom Attack Editor, from the Snort Format tab, click Other Actions → Import

    GUID-3D9793C9-5748-4D4E-96BB-D55785654B65-low.png
  7. Browse to the location of the rules file to be imported and select the rules file.

    GUID-24A25B5E-F39D-4210-A106-F822C4C7A8B6-low.png
  8. Select a Protection Category value.

    The Protection Category indicates the intent of the attack and the intended target. The list of Protection Categories is pre-defined and is provided by Trellix Advanced Research Center. In this scenario, the selected value is Advanced Protection Option/File Reputation

  9. Click Import

    After the import, the Import Results screen is displayed.

    GUID-9453D288-26D1-4CF7-BDF2-9FEC8EB960AD-low.jpg
  10. Close the Import Results screen.

  11. View the imported Snort rules.

    Know which rules converted successfully, which converted with warnings, and which failed to convert. For more information, see Viewing the imported Snort rules.

  12. View the imported Snort variables.

    Know which variables were imported and their classification type. For more information, see Viewing the Snort variables.

  13. Verify if the attacks in Published state are actually published in the policies.

    1. From the Resource Tree, select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS .

    2. Double-click one of the All Inclusive policies; for example, you can open the Default Testing policy.

    3. Click Attack Definitions tab.

    4. Sort the attacks based on Name and verify if the Snort rules are published.

    Note

    You can also create your own attack set profiles to define the exact environment resources you want to protect. For more information, see the Trellix Intrusion Prevention System Product Guide.

  14. Go to Devices → <Admin Domain Name> → Global → Device Manager.

  15. Select the devices on which you want to deploy the imported rules by selecting the check boxes. Click Sync.

    GUID-073B6DE2-60D8-4E2E-B4DE-9882AB1EF2DD-low.png

    The Bulk Sync window is displayed.

  16. Select Configuration & Signature Set from the window, and click Sync.

    This deploys the IPS policies that contain the new Snort rules to the selected Sensors.