These are the critical faults for a Manager and Central Manager.
Fault | Severity | Description/Cause | Action |
|---|---|---|---|
Suricata PCAP scheduler failed | Critical | The Suricata PCAP scheduler operation requires at least 10 GB of free space. Available disk space on the Manager installation drive : 7 GB. | To prevent operational issues, ensure you have the required free disk space. |
Deployment Error | Critical | The device has detected an error on signature segment {0}. The segment error cause is {2}, and the download type is {3} (The Manager will automatically make another attempt to deploy changes to the device). | Ensure the device is connected to the Manager and in good health. |
MDR Status Conflict | Critical | Detected MDR Status: Manager IP address / MDR Status as {0} / {1} and {2} / {3} | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
MDR Mode Conflict | Critical | MDR Mode: Manager IP address / MDR mode as {0} / {1} and {2} / {3} | Review the mode, status and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
MDR Pair IP Address Conflict | Critical | Device detected a conflict with MDR pair IP address: Manager-IP address / MDR action as {0} / {1} | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
MDR IP Address Type Conflict | Critical | Device detected a conflict with MDR IP address type as {0} instead of type {1}. | Review the mode, status, and configuration from each Manager console for accuracy. If needed, reset and recreate the MDR pair. |
Cluster Software Mismatch Status | Critical | Device software versions between primary cluster and secondary cluster is {0}. | |
SSL Decryption Certificate Deployment Failure | Critical | Deployment of SSL decryption certificates to the device {0} by the Manager failed. This could result from a network connectivity issue. (The Manager will continue to attempt deployment until it is successful.) | Consult the system log for details. |
Private GTI Cloud Certificate Deployment Failure | Critical | The Manager could not deploy the certificate required for communication with the private GTI cloud to device {0}. This error is due to a connectivity error between the Manager and the device. The Manager will automatically try to re-deploy the certificate to the device. | If the problem persists, consult the system log for details. |
Callback Detectors Deployment Failure | Critical | Deployment of Callback Detectors to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
NTBA Public Key Deployment Failure | Critical | Deployment of NTBA public key to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
Packet Capture Rule Deployment Failure | Critical | Deployment of packet capture rules to the device {0} by the Manager failed. This could be due to a network connectivity issue. | If the problem persists, consult the system log for details. |
Alert Storage Capacity Threshold Exceeded | Critical | Alert capacity: {0}. Current alert count: {1} | Prune and tune the database. |
Dropped Alerts and Packet Captures | Critical | {0}% capacity. Dropping alerts and packet captures. | Prune and tune the database. |
Update Server Connectivity Error | Critical | The Manager is unable to connect to the Trellix IPS Update Server. | Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable. |
Proxy Server Connectivity Error | Critical | The Manager is unable to connect to the configured proxy server {1}. | Consult the system log for details and confirm that the Manager can reach the proxy server and is using the proper proxy port. (Tip: You can test Manager connectivity through its proxy server on the Proxy Server page in the Manager GUI) |
Attack Packet Capture Save Error | Critical | The Manager is unable to save packet captures from attacks to the database. Error Message: {0}. | Ensure that the disk space allocated to the database is sufficient. |
Packet Log limit exceeded | Critical | Entries in packet log table has exceeded the current threshold [ {0} ] in database. | To recover the Manager from this state, Kindly fine tune the packet logging settings in your IPS policy. Also delete the old alerts and fine tune scheduled alert pruning settings. |
Alert Save Error | Critical | The Manager is unable to save alerts to the database. Error Message: {0}. | Ensure that the disk space allocated to the database is sufficient. |
Database Backup Error | Critical | The attempt to back up the Manager database failed. Error Message: {0}. | Check available disk space and that the necessary permissions to the directory have been given to the Manager application. |
Expired License Detected | Critical | A license has expired. | Replace expired and expiring licenses. |
Incompatible Custom Attacks | Critical | One or more custom attack is incompatible with the attacks in the current signature set. (Incompatibility often results from attack or signature definition overlap.) The following custom attack ids are in COMPILE FAILED state. {0} Please Check the CAE log for more details. | Update the custom attacks that show as having failed the Test Compile on the Custom Attacks window. |
Central Manager Custom Attack Synchronization Error | Critical | Port conflict detected during attempt to synchronize custom attack definitions from the Central Manager. Port {0} is already in use. | Free the port and restart the synchronization. |
Low JVM Memory | Critical | The Manager is experiencing high memory usage. Available system memory is low. Total memory (M): {0}, Free memory (M): {1}. | Reboot the host on which the Manager is running. |
Audit Failure and Manager Shutting Down | Critical | The Manager is unable to log an audit event and is therefore shutting down. | Consult the system log for the reason for audit failure. |
Signature Set Import Error | Critical | Sigset processing has failed in the Manager. This could be due to improper format or other technical reasons. Active sigset is empty, hence certain functionalities may not work fine. | Please download or import a valid sigset. If the issue persists, please contact the system administrator. |
Signature Set Download Failed due to tampered sigset | Critical | Signature set was tampered and the download failed from the Trellix IPS Update Server to the Manager. | N/A |
GTI Server Connectivity Error | Critical | The Manager is unable to communicate with the Trellix GTI Server. | Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable. |
MDR - System Time Synchronization Error | Critical | The two Managers in an MDR Pair must have the same operating system time. Otherwise, the device communication channels will experience disconnects. | Ensure both Managers are using the same time source and are synchronized with it. |
The MDR Connection is Down | Critical | The communication from {0} to {1} is down. | Confirm SSL (TCP 443) connectivity between the Managers (in both directions). |
Database Connectivity Error | Critical | The Manager is having trouble communicating with its database. Error Message: {0}. | Consult the database logs for errors and run the Manager Health Check to confirm the database is in good standing. |
Database Connectivity Lost | Critical | The Manager has lost connectivity with its database. Error Message: {0} | Check the status of the database service and consult its logs for errors. |
Database Integrity Error | Critical | Unable to locate index file for table: {0}. | Tune the database. |
Database Tuning Error | Critical | Database tuning failure. Error Message: {0}. | Run the Manager Health Check to confirm there is sufficient free disk space. |
Manager {0} Unreachable | Critical | Connectivity with Manager {0} has been lost. | Run the Manager Health Check on each Manager to check status and confirm basic connectivity. Then check connectivity between the Managers. |
Manager {0} MDR Error | Critical | Manager {0} detected in standby mode. The peer Manager {1} is either not reachable or does not have {2} data. | If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active. |
Manager {0} MDR Error | Critical | Manager {0} used to be the {1}/{2} MDR configuration and is now the {3}/{4} MDR configuration, and the primary Manager {5} is not active and its peer {6} does not have {7} configured. | If the above Managers are Trellix IPS Central Managers, make the Central Manager with the Trellix IPS Manager data active or recreate the MDR Pair. If the Managers are Trellix IPS Managers, make the Manager with the Trellix IPS Central Manager data active. |
MDR Configuration Conflict for Manager {0} | Critical | Manager {0} is in {1} mode, and its peer Manager {2} is in {3} mode. | Recreate the MDR Pair. |
MDR Pair Status Changed {0} | Critical | The {0} Manager is {1}/{2} and now primary and secondary are {3}/{4}. | Correct the MDR Pair status. If needed, recreate the MDR Pair. |
Vulnerability Data Import Error | Critical | {0} | Consult the system log for details and contact Trellix Technical Support if the problem continues. |
Simultaneous FIPS Role Login | Critical | Users from all three FIPS mode roles (Audit Administrator, Crypto Administrator and Security Administrator) have logged onto the Manager at the same time. | |
AD Groups Size Exceeded | Critical | Currently TLC integration supports only {0} AD groups. This has been exceeded, so the Sensor behavior cannot be guaranteed until these numbers are brought down from "{1}". | Reduce the number of groups in Active Directory. |
AD Groups Size Limitation | Critical | Currently TLC integration supports only {0} AD groups. Sensor version {1} cannot accommodate {2} AD groups" . | Reduce the number of groups in Active Directory. |
Malware File Archive Disk Usage ({0}) | Critical | The disk usage for archived "{0}" has reached {1} of the maximum allowed ({2}). New files of this type will no longer be saved to the disk. | Prune/delete unwanted files, increase the maximum disk space, or both. |
Insightix LDAP Server Communication Error | Critical | The link between the NAC Sensor and the Insightix LDAP Server is down. | |
Communication Error with Trellix Intelligent Sandbox Device ({0}) | Critical | The Manager is unable to establish connectivity with the Trellix Intelligent Sandbox device "{0}". | Confirm connectivity between the devices, port, and credentials used to send Intelligent Sandbox files. |
Solr Alert Core Indexing Error | Critical | Solr indexing failed for core: "{0}" due to error - "{1}". | The Solr index may need to be recreated from the database. |
Solr AppAlert Core Indexing Error | Critical | Solr indexing failed for core: "{0}" due to error - "{1}". | The Solr index may be corrupted. |
Solr Directory Backup Error | Critical | Backing up Solr core {0} encountered an error. | Check available disk space and Solr directory settings. |
Database Backup File Creation Error | Critical | Creation of the backup file encountered an error. | Check the available disk space on backup drive. |
Solr Directory Backup Error | Critical | Backing up Solr core {0} encountered an error. | Check the available disk space and Solr directory settings. |
Importing alert data to Solr failed | Critical | Importing data to solr post Trellix IPS upgrade failed. | Please contact Trellix Technical Support. |
Cloud Provider Access Error | Critical | An activity with the cloud provider failed due to access credentials. | Confirm/edit the access credentials and check connectivity to the cloud. |
Trellix Virtual IPS Controller disconnected | Critical | The Manager is unable to communicate with Trellix Virtual IPS Controller: {0} ({1}) | Confirm that the Controller instance is running and that it is using the proper Manager IP address ({2}) in its user data. Also ensure that the Controller is allowed to connect to the Manager over TCP 443. (Check both local/remote firewall and cloud access rules.) Finally, consult controller.log on the Controller and cim_web.log on the Manager for more details. |
Trellix Virtual IPS Controller Connectivity Error | Critical | An activity with the Controller failed due to connectivity problems. | Confirm connectivity between the Manager and the Controller. (Tip: Connectivity issues are often due to lack of access. To isolate the issue, temporarily remove all access restrictions to see if the problem is resolved) |
AWS Cloud Access Error | Critical | An activity with the AWS cloud failed because of access credentials. | Confirm/edit the access credentials used for AWS connectivity. |
Trellix Virtual IPS Controller Upgrade Error | Critical | An activity with the Controller failed because of {0} | Confirm connectivity between the Manager and the Controller. (Tip: Connectivity issues are often due to lack of access. To isolate the issue, temporarily remove all access restrictions to see if the problem is resolved) |
Outbound Decryption - Re-Signing Certificate Deployment Error | Critical | The re-signing SSL certificate could not be deployed to one or more devices. This is due to the addition of the device to the Manager after importing a custom re-signing certificate (The Manager no longer has the re-signing certificate from which it can generate a copy for the new device). Outbound decryption will not function as intended. | Re-import the custom re-signing certificate. |
Manager CSR File Generation Error | Critical | An error occurred while generating a CSR file for the Manager. (The CSR file is used to create a CA-signed certificate, which is in turn used by the Manager when the devices establish trust with it using their own CA-signed certificates) | Confirm that the App/CCMigration folder has been created on the Manager file system and the NSMks.ks file has been created inside it. If missing, confirm that the Manager has proper permissions to the file system. Use of special characters when creating the CSR may also lead to an error. If using special characters, try to generate the CSR again without them. Otherwise, consult the system log for details. |
Manager Trust Establishment Ports Error | Critical | An error occurred while the Manager was attempting to close the ports on which it had been listening to establish trust with the device using CA-signed certificates. | Confirm that CA-signed channel ports 8506/8507/8508 are open on the Manager and try again. |
Trust Establishment Error | Critical | The trust request has failed. Error message: {0}. | Please verify reachability between Trellix IPS Central Manager and Trellix IPS Manager |
Trust Establishment Error | Critical | The trust request has failed because Trellix IPS Manager {0} may not be reachable. | Confirm the Trellix IPS Manager IP address and that its service is up and running. |
Trust Establishment Error | Critical | The trust request has failed because Trellix IPS Manager {0} has not yet configured. | Configure Trellix IPS Manager with Trellix IPS Central Manager. |
Trust Establishment Error | Critical | The trust request has failed because the {0} already has a trust using the configured name. The previous trust with {1} may represent the Trellix IPS Manager or another. | Delete and re-add the configuration with Trellix IPS Central Manager. |
Trust Establishment Error | Critical | The trust request has failed because the configured Trellix IPS Manager is in MDR mode, and no active {0} Trellix IPS Manager has been detected with which to establish the trust. | Please make one of the Trellix IPS Managers as Active in case of MDR prior to configure with Trellix IPS Central Manager. |
Disk Space Warning | Critical | The drive on which the Manager database is installed ({1}) is {0} full. | Prune and tune the database. |
NI Connectivity Failed | Critical | Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed. | Please check authorization token input is correct. |
NI Connectivity Failed | Critical | Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed due to missing Application ID. | Please check request to NI contains Application Identifier. |
NI Connectivity Failed | Critical | Connectivity to NI server {0} with group name {1} from Trellix IPS Manager failed. | Please check network connection and reachability of NI server from Trellix IPS Manager. |
TSSDK Cert file not found | Critical | The device is not able to find TSSDK Cert bundle | Confirm if file has been sent successfully from IPS Manager |
TSSDK Cert file parsing error | Critical | The device is not able to parse TSSDK Cert bundle | Confirm if file sent from IPS Manager is valid |
Name Resolution Error | Critical | Domain Name Resolution has failed | Confirm name resolution connectivity on the device |