The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS CLI enhancements

Prev Next

Following new Sensor CLI commands are available:

Normal Mode
CLI Command Description
clear ssl outbound urlcache Clears the URL cache generated for outbound SSL traffic where exceptions are set for specific URLs.
set hypervisor server ip Sets the IPv4 or IPv6 address for the hypervisor server.
show snort config Displays the Snort engine configuration as selected through the Manager.
show ssl config Shows the configuration details for SSL on the Sensor.
show ssl stats inbound agents Displays the number of Agents connected to the Sensor.
show sslagentaccesscontrol status Displays the SSL Agent status and the number of connections from the Agents to the Sensor.
show suricata enginestats Displays the statistics of the Suricata Snort engine.
show suricata sbstats Displays the rule, packet, and alert statistics of the Suricata Snort engine.
sslagentaccesscontrol resetlist Deletes the entire access list of SSL agents that are configured for accessing the Sensor.
Debug Mode
CLI Command Description
packetcapture Starts or stops packet capture in VMware NSX, AWS, and Azure Platforms, or uploads captured packet files.
set gzip decode limit Sets maximum size for http response to be decompressed upon gzip encoding.
show ssl stats sensor Displays the Inbound SSL Task connection, packet, and session statistics.
suricata Enables or disables packet forwarding to the Suricata engine.

Following Sensor CLI commands are updated:

Normal Mode
CLI Command Description
clear gti server This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
resolve gti server This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
set gtiserver ip This command works only for the Public GTI cloud and only when the Private GTI cloud is disabled in the Manager.
show gti config Output displays both Public and Private GTI could configuation information.
show ssl stats Earlier it displayed information only for the inbound SSL traffic with RSA ciphers. This command now displays infromation related to the outbound SSL traffic and the inbound SSL traffic with the DHE/ECDHE ciphers.

Following Sensor CLI commands are removed:

Normal Mode
CLI Command
clear tcp-proxy statistics
increasemgmtprocessing
show powersupply
Debug Mode
CLI Command
clearactiveflows
flashcheck
reset ratelimitstats
show fe stat
show feswitch port
show gmac
show ratelimit drops
show ratelimit markstats

For more information, see the CLI commands section in the Trellix Intrusion Prevention System Product Guide.