These are the critical faults for a Manager and Central Manager.
| Fault | Severity | Description/Cause | Action |
|---|---|---|---|
| Deployment Error | Critical | The device has detected an error on signature segment {0}. The segment error cause is {2}, and the download type is {3} (The Manager will automatically make another attempt to deploy changes to the device). | Ensure the device is connected to the Manager and in good health. |
| MDR Status Conflict | Critical | Detected MDR Status: Manager IP address / MDR Status as {0} / {1} and {2} / {3} | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
| MDR Mode Conflict | Critical | MDR Mode: Manager IP address / MDR mode as {0} / {1} and {2} / {3} | Review the mode, status and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
| MDR Pair IP Address Conflict | Critical | Device detected a conflict with MDR pair IP address: Manager-IP address / MDR action as {0} / {1} | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
| MDR IP Address Type Conflict | Critical | Device detected a conflict with MDR IP address type as {0} instead of type {1}. | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
| Cluster Software Mismatch Status | Critical | Device software versions between primary cluster and secondary cluster is {0}. | |
| SSL Decryption Certificate Deployment Failure | Critical | Deployment of SSL decryption certificates to the device {0} by the Manager failed. This could result from a network connectivity issue. (The Manager will continue to attempt deployment until it is successful.) | Consult the system log for details. |
| Private GTI Cloud Certificate Deployment Failure | Critical | The Manager could not deploy the certificate required for communication with the private GTI cloud to device {0}. This error is due to a connectivity error between the Manager and the device. The Manager will automatically try to re-deploy the certificate to the device. | If the problem persists, consult the system log for details. |
| Callback Detectors Deployment Failure | Critical | Deployment of Callback Detectors to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
| NTBA Public Key Deployment Failure | Critical | Deployment of NTBA public key to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
| Packet Capture Rule Deployment Failure | Critical | Deployment of packet capture rules to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
| Alert Storage Capacity Threshold Exceeded | Critical | Alert capacity: {0}. Current alert count: {1} | Prune and tune the database. |
| Dropped Alerts and Packet Captures | Critical | {0}% capacity. Dropping alerts and packet captures. | Prune and tune the database. |
| Update Server Connectivity Error | Critical | The Manager is unable to connect to the Trellix IPS Update Server. | Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable. |
| Proxy Server Connectivity Error | Critical | The Manager is unable to connect to the configured proxy server {1}. | Consult the system log for details and confirm that the Manager can reach the proxy server and is using the proper proxy port. (Tip: You can test Manager connectivity through its proxy server on the Proxy Server page in the Manager GUI) |
| Attack Packet Capture Save Error | Critical | The Manager is unable to save packet captures from attacks to the database. Error Message: {0}. | Ensure that the disk space allocated to the database is sufficient. |
| Alert Save Error | Critical | The Manager is unable to save alerts to the database. Error Message: {0}. | Ensure that the disk space allocated to the database is sufficient. |
| Database Backup Error | Critical | The attempt to back up the Manager database failed. Error Message: {0}. | Check available disk space and that the necessary permissions to the directory have been given to the Manager application. |
| Expired License Detected | Critical | A license has expired. | Replace expired and expiring licenses. |
| Incompatible Custom Attacks | Critical | One or more custom attack is incompatible with the attacks in the current signature set. (Incompatibility often results from attack or signature definition overlap.) | Update the custom attacks that show as having failed the Test Compile on the Custom Attacks window. |
| Central Manager Custom Attack Synchronization Error | Critical | Port conflict detected during attempt to synchronize custom attack definitions from the Central Manager. Port {0} is already in use. | Free the port and restart the synchronization. |
| Low JVM Memory | Critical | The Manager is experiencing high memory usage. Available system memory is low. Total memory (M): {0}, Free memory (M): {1}. | Reboot the host on which the Manager is running. |
| Audit Failure and Manager Shutting Down | Critical | The Manager is unable to log an audit event and is therefore shutting down. | Consult the system log for the reason for audit failure. |
| Signature Set Import Error | Critical | The attempt to import the signature set into the Manager failed. | Consult the system log for details and try again with a known-good signature set. |
| GTI Server Connectivity Error | Critical | The Manager is unable to communicate with the Trellix GTI Server. | Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable. |
| MDR - System Time Synchronization Error | Critical | The two Managers in an MDR Pair must have the same operating system time. Otherwise, the device communication channels will experience disconnects. | Ensure both Managers are using the same time source and are synchronized with it. |
| The MDR Connection is Down | Critical | The communication from {0} to {1} is down. | Confirm connectivity between the Managers. |
| Database Connectivity Error | Critical | The Manager is having trouble communicating with its database. Error Message: {0}. | Consult the database logs for errors and run the Manager Health Check to confirm the database is in good standing. |
| Database Connectivity Lost | Critical | The Manager has lost connectivity with its database. Error Message: {0} | Check the status of the database service and consult its logs for errors. |
| Database Integrity Error | Critical | Unable to locate index file for table: {0}. | Tune the database. |
| Database Tuning Error | Critical | Database tuning failure. Error Message: {0}. | Run the Manager Health Check to confirm there is sufficient free disk space. |
| Manager {0} Unreachable | Critical | Connectivity with Manager {0} has been lost. | Run the Manager Health Check on each Manager to check status and confirm basic connectivity. Then check connectivity between the Managers. |
| Manager {0} MDR Error | Critical | Manager {0} detected in standby mode. The peer Manager {1} is either not reachable or does not have {2} data. | If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active. |
| Manager {0} MDR Error | Critical | Manager {0} used to be the {1}/{2} MDR configuration and is now the {3}/{4} MDR configuration, and the primary Manager {5} is not active and its peer {6} does not have {7} configured. | If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active. |
| MDR Configuration Conflict for Manager {0} | Critical | Manager {0} is in {1} mode, and its peer Manager {2} is in {3} mode. | Recreate the MDR Pair. |
| MDR Pair Status Changed {0} | Critical | The {0} Manager is {1}/{2} and now primary and secondary are {3}/{4}. | Correct the MDR Pair status. If needed, recreate the MDR Pair. |
| Vulnerability Data Import Error | Critical | {0} | Consult the system log for details and contact Trellix Technical Support if the problem continues. |
| On-Demand Vulnerability Scan Error | Critical | Scan failed because the connection to Vulnerability Manager Scan Engine was refused. {0},{1} | Check connectivity to the Vulnerability scan engine. |
| Simultaneous FIPS Role Login | Critical | Users from all three FIPS mode roles (Audit Administrator, Crypto Administrator and Security Administrator) have logged onto the Manager at the same time. | |
| AD Groups Size Exceeded | Critical | Currently MLC integration supports only {0} AD groups. This has been exceeded, so the Sensor behavior cannot be guaranteed until these numbers are brought down from "{1}". | Reduce the number of groups in Active Directory. |
| AD Groups Size Limitation | Critical | Currently MLC integration supports only {0} AD groups. Sensor version {1} cannot accommodate {2} AD groups" . | Reduce the number of groups in Active Directory. |
| Malware File Archive Disk Usage ({0}) | Critical | The disk usage for archived "{0}" has reached {1} of the maximum allowed ({2}). New files of this type will no longer be saved to the disk. | Prune/delete unwanted files, increase the maximum disk space, or both. |
| Insightix LDAP Server Communication Error | Critical | The link between the NAC Sensor and the Insightix LDAP Server is down. | |
| Communication Error with Trellix Intelligent Sandbox Device ({0}) | Critical | The Manager is unable to establish connectivity with the Trellix Intelligent Sandbox device "{0}". | Confirm connectivity between the devices, port, and credentials used to send Intelligent Sandbox files. |
| Solr Alert Core Indexing Error | Critical | Solr indexing failed for core: "{0}" due to error - "{1}". | The Solr index may need to be recreated from the database. |
| Solr AppAlert Core Indexing Error | Critical | Solr indexing failed for core: "{0}" due to error - "{1}". | The Solr index may be corrupted. |
| Solr Directory Backup Error | Critical | Backing up Solr core {0} encountered an error. | Check available disk space and Solr directory settings. |
| Database Backup File Creation Error | Critical | Creation of the backup file encountered an error. | Check the available disk space on backup drive. |
| Solr Directory Backup Error | Critical | Backing up Solr core {0} encountered an error. | Check the available disk space and Solr directory settings. |
| Cloud Provider Access Error | Critical | An activity with the cloud provider failed due to access credentials. | Confirm/edit the access credentials and check connectivity to the cloud. |
| Outbound Decryption - Re-Signing Certificate Deployment Error | Critical | The re-signing SSL certificate could not be deployed to one or more devices. This is due to the addition of the device to the Manager after importing a custom re-signing certificate (The Manager no longer has the re-signing certificate from which it can generate a copy for the new device). Outbound decryption will not function as intended. | Re-import the custom re-signing certificate. |
| Manager CSR File Generation Error | Critical | An error occurred while generating a CSR file for the Manager. (The CSR file is used to create a CA-signed certificate, which is in turn used by the Manager when the devices establish trust with it using their own CA-signed certificates) | Confirm that the App/CCMigration folder has been created on the Manager file system and the NSMks.ks file has been created inside it. If missing, confirm that the Manager has proper permissions to the file system. Use of special characters when creating the CSR may also lead to an error. If using special characters, try to generate the CSR again without them. Otherwise, consult the system log for details. |
| Manager Trust Establishment Ports Error | Critical | An error occurred while the Manager was attempting to close the ports on which it had been listening to establish trust with the device using CA-signed certificates. | Confirm that CA-signed channel ports 8506/8507/8508 are open on the Manager and try again. |
| Trust Establishment Error | Critical | The trust request has failed because Trellix IPS Manager {0} may not be reachable. | Confirm the Trellix IPS Manager IP address and that its service is up and running. |
| Trust Establishment Error | Critical | The trust request has failed because Trellix IPS Manager {0} has not yet configured. | Configure Trellix IPS Manager with Trellix IPS Central Manager. |
| Trust Establishment Error | Critical | The trust request has failed because the {0} already has a trust using the configured name. The previous trust with {1} may represent the Trellix IPS Manager or another. | Delete and re-add the configuration with Trellix IPS Central Manager. |
| Trust Establishment Error | Critical | The trust request has failed because the configured Trellix IPS Manager is in MDR mode, and no active {0} Trellix IPS Manager has been detected with which to establish the trust. | Make one of the Trellix IPS Managers as Active in case of MDR prior to configure with Trellix IPS Central Manager. |
| Disk Space Warning | Critical | The drive on which the Manager database is installed ({1}) is {0} full. | Prune and tune the database. |