Using the Trellix IPS Central Manager, you can manage custom attacks for the corresponding Managers. Functionally, the Custom Attack Editor of a Central Manager is the same as that of a Manager. So, see the earlier sections in this document for information on how to use the Editor for Trellix IPS Custom Attacks and Snort Custom Attacks.
The summary of managing custom attacks from the Central Manager is as follows:
Create the custom attack definitions using the Custom Attack Editor in the Central Manager.
Save the custom attacks in the Central Manager server database.
Synchronize the policies of the constituent Managers.
From the Resource Tree of the Central Manager, select Manager List → Policy Synchronization.
Select the Synchronization Type for the required Managers and then click Synchronize.
View the status of the synchronization. Check the Status of Activities section on the Home page of the Central Manager.
Update the Sensors with the configuration change.
Log on to the required Manager.
Update the relevant Sensors with the policy change.
Repeat this process for the other Managers.