The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager critical faults

Prev Next

These are the critical faults for a Manager and Central Manager.

Fault

Severity

Description/Cause

Action

Suricata PCAP scheduler failed

Critical

The Suricata PCAP scheduler operation requires at least 10 GB of free space.

Available disk space on the Manager installation drive : 7 GB.

To prevent operational issues, ensure you have the required free disk space.

Deployment Error

Critical

The device has detected an error on signature segment {0}. The segment error cause is {2}, and the download type is {3} (The Manager will automatically make another attempt to deploy changes to the device).

Ensure the device is connected to the Manager and in good health.

MDR Status Conflict

Critical

Detected MDR Status: Manager IP address / MDR Status as {0} / {1} and {2} / {3}

Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair.

MDR Mode Conflict

Critical

MDR Mode: Manager IP address / MDR mode as {0} / {1} and {2} / {3}

Review the mode, status and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair.

MDR Pair IP Address Conflict

Critical

Device detected a conflict with MDR pair IP address: Manager-IP address / MDR action as {0} / {1}

Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair.

MDR IP Address Type Conflict

Critical

Device detected a conflict with MDR IP address type as {0} instead of type {1}.

Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair.

Cluster Software Mismatch Status

Critical

Device software versions between primary cluster and secondary cluster is {0}.

SSL Decryption Certificate Deployment Failure

Critical

Deployment of SSL decryption certificates to the device {0} by the Manager failed. This could result from a network connectivity issue. (The Manager will continue to attempt deployment until it is successful.)

Consult the system log for details.

Private GTI Cloud Certificate Deployment Failure

Critical

The Manager could not deploy the certificate required for communication with the private GTI cloud to device {0}. This error is due to a connectivity error between the Manager and the device. The Manager will automatically try to re-deploy the certificate to the device.

If the problem persists, consult the system log for details.

Callback Detectors Deployment Failure

Critical

Deployment of Callback Detectors to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

NTBA Public Key Deployment Failure

Critical

Deployment of NTBA public key to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

Packet Capture Rule Deployment Failure

Critical

Deployment of packet capture rules to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

Alert Storage Capacity Threshold Exceeded

Critical

Alert capacity: {0}. Current alert count: {1}

Prune and tune the database.

Dropped Alerts and Packet Captures

Critical

{0}% capacity. Dropping alerts and packet captures.

Prune and tune the database.

Update Server Connectivity Error

Critical

The Manager is unable to connect to the Trellix IPS Update Server.

Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.

Proxy Server Connectivity Error

Critical

The Manager is unable to connect to the configured proxy server {1}.

Consult the system log for details and confirm that the Manager can reach the proxy server and is using the proper proxy port. (Tip: You can test Manager connectivity through its proxy server on the Proxy Server page in the Manager GUI)

Attack Packet Capture Save Error

Critical

The Manager is unable to save packet captures from attacks to the database. Error Message: {0}.

Ensure that the disk space allocated to the database is sufficient.

Packet Log limit exceeded

Critical

Entries in packet log table has exceeded the current threshold [ {0} ] in database.

To recover the Manager from this state, Kindly fine tune the packet logging settings in your IPS policy. Also delete the old alerts and fine tune scheduled alert pruning settings.

Alert Save Error

Critical

The Manager is unable to save alerts to the database. Error Message: {0}.

Ensure that the disk space allocated to the database is sufficient.

Database Backup Error

Critical

The attempt to back up the Manager database failed. Error Message: {0}.

Check available disk space and that the necessary permissions to the directory have been given to the Manager application.

Expired License Detected

Critical

A license has expired.

Replace expired and expiring licenses.

Incompatible Custom Attacks

Critical

One or more custom attack is incompatible with the attacks in the current signature set. (Incompatibility often results from attack or signature definition overlap.) The following custom attack ids are in COMPILE FAILED state. {0} Please Check the CAE log for more details.

Update the custom attacks that show as having failed the Test Compile on the Custom Attacks window.

Central Manager Custom Attack Synchronization Error

Critical

Port conflict detected during attempt to synchronize custom attack definitions from the Central Manager. Port {0} is already in use.

Free the port and restart the synchronization.

Low JVM Memory

Critical

The Manager is experiencing high memory usage. Available system memory is low. Total memory (M): {0}, Free memory (M): {1}.

Reboot the host on which the Manager is running.

Audit Failure and Manager Shutting Down

Critical

The Manager is unable to log an audit event and is therefore shutting down.

Consult the system log for the reason for audit failure.

Signature Set Import Error

Critical

Sigset processing has failed in the Manager. This could be due to improper format or other technical reasons. Active sigset is empty, hence certain functionalities may not work fine.

Please download or import a valid sigset. If the issue persists, please contact the system administrator.

Signature Set Download Failed due to tampered sigset

Critical

Signature set was tampered and the download failed from the Trellix IPS Update Server to the Manager.

N/A

GTI Server Connectivity Error

Critical

The Manager is unable to communicate with the Trellix GTI Server.

Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.

MDR - System Time Synchronization Error

Critical

The two Managers in an MDR Pair must have the same operating system time. Otherwise, the device communication channels will experience disconnects.

Ensure both Managers are using the same time source and are synchronized with it.

The MDR Connection is Down

Critical

The communication from {0} to {1} is down.

Confirm SSL (TCP 443) connectivity between the Managers (in both directions).

Database Connectivity Error

Critical

The Manager is having trouble communicating with its database. Error Message: {0}.

Consult the database logs for errors and run the Manager Health Check to confirm the database is in good standing.

Database Connectivity Lost

Critical

The Manager has lost connectivity with its database. Error Message: {0}

Check the status of the database service and consult its logs for errors.

Database Integrity Error

Critical

Unable to locate index file for table: {0}.

Tune the database.

Database Tuning Error

Critical

Database tuning failure. Error Message: {0}.

Run the Manager Health Check to confirm there is sufficient free disk space.

Manager {0} Unreachable

Critical

Connectivity with Manager {0} has been lost.

Run the Manager Health Check on each Manager to check status and confirm basic connectivity. Then check connectivity between the Managers.

Manager {0} MDR Error

Critical

Manager {0} detected in standby mode. The peer Manager {1} is either not reachable or does not have {2} data.

If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active.

Manager {0} MDR Error

Critical

Manager {0} used to be the {1}/{2} MDR configuration and is now the {3}/{4} MDR configuration, and the primary Manager {5} is not active and its peer {6} does not have {7} configured.

If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active.

MDR Configuration Conflict for Manager {0}

Critical

Manager {0} is in {1} mode, and its peer Manager {2} is in {3} mode.

Recreate the MDR Pair.

MDR Pair Status Changed {0}

Critical

The {0} Manager is {1}/{2} and now primary and secondary are {3}/{4}.

Correct the MDR Pair status. If needed, recreate the MDR Pair.

Vulnerability Data Import Error

Critical

{0}

Consult the system log for details and contact Trellix Technical Support if the problem continues.

Simultaneous FIPS Role Login

Critical

Users from all three FIPS mode roles (Audit Administrator, Crypto Administrator and Security Administrator) have logged onto the Manager at the same time.

AD Groups Size Exceeded

Critical

Currently TLC integration supports only {0} AD groups. This has been exceeded, so the Sensor behavior cannot be guaranteed until these numbers are brought down from "{1}".

Reduce the number of groups in Active Directory.

AD Groups Size Limitation

Critical

Currently TLC integration supports only {0} AD groups. Sensor version {1} cannot accommodate {2} AD groups" .

Reduce the number of groups in Active Directory.

Malware File Archive Disk Usage ({0})

Critical

The disk usage for archived "{0}" has reached {1} of the maximum allowed ({2}). New files of this type will no longer be saved to the disk.

Prune/delete unwanted files, increase the maximum disk space, or both.

Insightix LDAP Server Communication Error

Critical

The link between the NAC Sensor and the Insightix LDAP Server is down.

Communication Error with Trellix Intelligent Sandbox Device ({0})

Critical

The Manager is unable to establish connectivity with the Trellix Intelligent Sandbox device "{0}".

Confirm connectivity between the devices, port, and credentials used to send Intelligent Sandbox files.

Solr Alert Core Indexing Error

Critical

Solr indexing failed for core: "{0}" due to error - "{1}".

The Solr index may need to be recreated from the database.

Solr AppAlert Core Indexing Error

Critical

Solr indexing failed for core: "{0}" due to error - "{1}".

The Solr index may be corrupted.

Solr Directory Backup Error

Critical

Backing up Solr core {0} encountered an error.

Check available disk space and Solr directory settings.

Database Backup File Creation Error

Critical

Creation of the backup file encountered an error.

Check the available disk space on backup drive.

Solr Directory Backup Error

Critical

Backing up Solr core {0} encountered an error.

Check the available disk space and Solr directory settings.

Importing alert data to Solr failed

Critical

Importing data to solr post Trellix IPS upgrade failed.

Please contact Trellix Technical Support.

Cloud Provider Access Error

Critical

An activity with the cloud provider failed due to access credentials.

Confirm/edit the access credentials and check connectivity to the cloud.

Trellix Virtual IPS Controller disconnected

Critical

The Manager is unable to communicate with Trellix Virtual IPS Controller: {0} ({1})

Confirm that the Controller instance is running and that it is using the proper Manager IP address ({2}) in its user data. Also ensure that the Controller is allowed to connect to the Manager over TCP 443. (Check both local/remote firewall and cloud access rules.) Finally, consult controller.log on the Controller and cim_web.log on the Manager for more details.

Trellix Virtual IPS Controller Connectivity Error

Critical

An activity with the Controller failed due to connectivity problems.

Confirm connectivity between the Manager and the Controller. (Tip: Connectivity issues are often due to lack of access. To isolate the issue, temporarily remove all access restrictions to see if the problem is resolved)

AWS Cloud Access Error

Critical

An activity with the AWS cloud failed because of access credentials.

Confirm/edit the access credentials used for AWS connectivity.

Trellix Virtual IPS Controller Upgrade Error

Critical

An activity with the Controller failed because of {0}

Confirm connectivity between the Manager and the Controller. (Tip: Connectivity issues are often due to lack of access. To isolate the issue, temporarily remove all access restrictions to see if the problem is resolved)

Outbound Decryption - Re-Signing Certificate Deployment Error

Critical

The re-signing SSL certificate could not be deployed to one or more devices. This is due to the addition of the device to the Manager after importing a custom re-signing certificate (The Manager no longer has the re-signing certificate from which it can generate a copy for the new device). Outbound decryption will not function as intended.

Re-import the custom re-signing certificate.

Manager CSR File Generation Error

Critical

An error occurred while generating a CSR file for the Manager. (The CSR file is used to create a CA-signed certificate, which is in turn used by the Manager when the devices establish trust with it using their own CA-signed certificates)

Confirm that the App/CCMigration folder has been created on the Manager file system and the NSMks.ks file has been created inside it. If missing, confirm that the Manager has proper permissions to the file system. Use of special characters when creating the CSR may also lead to an error. If using special characters, try to generate the CSR again without them. Otherwise, consult the system log for details.

Manager Trust Establishment Ports Error

Critical

An error occurred while the Manager was attempting to close the ports on which it had been listening to establish trust with the device using CA-signed certificates.

Confirm that CA-signed channel ports 8506/8507/8508 are open on the Manager and try again.

Trust Establishment Error

Critical

The trust request has failed. Error message: {0}.

Please verify reachability between Trellix IPS Central Manager and Trellix IPS Manager

Trust Establishment Error

Critical

The trust request has failed because Trellix IPS Manager {0} may not be reachable.

Confirm the Trellix IPS Manager IP address and that its service is up and running.

Trust Establishment Error

Critical

The trust request has failed because Trellix IPS Manager {0} has not yet configured.

Configure Trellix IPS Manager with Trellix IPS Central Manager.

Trust Establishment Error

Critical

The trust request has failed because the {0} already has a trust using the configured name. The previous trust with {1} may represent the Trellix IPS Manager or another.

Delete and re-add the configuration with Trellix IPS Central Manager.

Trust Establishment Error

Critical

The trust request has failed because the configured Trellix IPS Manager is in MDR mode, and no active {0} Trellix IPS Manager has been detected with which to establish the trust.

Please make one of the Trellix IPS Managers as Active in case of MDR prior to configure with Trellix IPS Central Manager.

Disk Space Warning

Critical

The drive on which the Manager database is installed ({1}) is {0} full.

Prune and tune the database.

NI Connectivity Failed

Critical

Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed.

Please check authorization token input is correct.

NI Connectivity Failed

Critical

Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed due to missing Application ID.

Please check request to NI contains Application Identifier.

NI Connectivity Failed

Critical

Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed.

Please check network connection and reachability of NI server from Trellix IPS Manager.

TSSDK Cert file not found

Critical

The device is not able to find TSSDK Cert bundle

Confirm if file has been sent successfully from IPS Manager

TSSDK Cert file parsing error

Critical

The device is not able to parse TSSDK Cert bundle

Confirm if file sent from IPS Manager is valid

Name Resolution Error

Critical

Domain Name Resolution has failed

Confirm name resolution connectivity on the device