The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

localsig ttl hours

Prev Next

Changes the time-to-live (TTL) value for local signature rules. The default TTL value is 24 hours.

  • If the locally generated rule receives no hit within 24 hours from the time it was generated, then the rule expires after 24 hours.

  • If the rule receives a hit within 24 hours, then its TTL is extended for another 24 hours.

Syntax

localsig ttl hours <hours>

Parameters

Specify the number of hours for a local signature rule to be extended after a hit. The default is 24 hours. Valid values are integers ranging from 1 to 168.

Example

The following example changes the local signature TTL value to 100 hours.

  • If the rule receives no hit from the time it was generated, then the rule will expire after 100 hours.

  • If the rule receives a hit, then the rule will be extended for 100 hours.

hostname (config) # localsig ttl hours 100

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 8.3.0

  • Network Security: Release 8.2.0

  • Malware Analysis: Release 8.2.0

  • File Protect: Release 8.2.0

  • Intelligent Virtual Execution - Server: Release 8.2.0

  • Email Security — Server: Release 8.1.4