The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS event notifications

Prev Next

In addition to displaying IPS events and IPS alerts in the IPS Events page of the Web UI, you can configure the platform to send FireEye notifications for IPS events. IPS event notifications contain the following information:

  • Date and time of the event

  • IPS rule name

  • Common Vulnerabilities and Exposures (CVE) ID (if the IPS rule is associated with a CVE vulnerability)

  • Client or server attack target

  • Blocking action taken

Event notification methods and IPS event severity levels

You can enable IPS event notification using any of the FireEye notification services that are enabled and configured for the base Network Security appliance. The platform sends IPS alert notifications to remote syslog servers for all severity levels. For all other event notification methods, the system sends alert notifications for critical IPS events or for IPS alerts (MVX-correlated IPS events).

Trellix event notification method

Criteria for IPS event notification

rsyslog—Log notification messages to remote syslog servers.

Minor severity (1–3),

Major severity (4–6),

Critical severity (7–10

email—Send notification email messages using SMTP.

Critical severity or

MVX‑correlated

http—Post notification messages to Web servers using HTTP.

Critical severity or

MVX‑correlated

snmp—Send traps to SNMP servers

Critical severity or

MVX‑correlated

Configuration details are provided in the Initial configuration of IPS section of this guide. See Configuring how IPS event notifications are sent.

Delivery modes for IPS event notifications

If IPS event notifications are configured, the system uses one of the following delivery modes:

  • instant—Send notification only when an IPS event is detected. This is the default value.

  • confirmation—Send notification only if an IPS event is verified to be either an IPS alert or not an attack.

  • dual—Send notifications both when an IPS event is detected and when an attack has been confirmed.

By default, the system is configured to use instant delivery mode, which is useful in an organization that archives notifications and then filters and analyzes the information later. When you first activate IPS features, we recommend that you use dual mode so that you see both detection and confirmation of IPS events. If your organization does not archive the volume of notifications generated in this mode, you can decrease the volume of notifications by using confirmation mode.

Configuration details are provided in the Initial configuration of IPS section of this guide. See Testing IPS event notifications.

Test-fire events for IPS event notification testing

You can test your configuration of IPS event notifications by using the test-fire feature for FireEye event notifications. The platform generates an IPS event of severity level 8, which should trigger event notifications for all notification methods configured on the platform.

  • After you initiate an IPS test-fire event, the event appears in the IPS Events page for approximately 5 minutes before it disappears from the page display and the events database. IPS test-fire events are listed with the rule name IPS‑TEST‑FIRE: Malicious PDF Downloaded.

  • If a configured notification method (email, HTTP, rsyslog, or SNMP) fails, correct the notification settings, and then repeat the test.

Testing details are provided in the Initial configuration of IPS section of this guide. See Configuring when IPS event notifications are sent