The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager error faults

Prev Next

These are the error faults for a Manager and Central Manager.

Fault Severity Description/Cause Action
GAM Updating Error Error Device is detecting an error on av-dat file segment {0}. The segment error cause is {2}, and the download type is {3}. (The Manager will automatically make another attempt to deploy the update to the device.) Ensure the device is connected to the Manager and in good health.
Deployment Failure Error The attempt by the Manager to deploy changes to device {0} failed during device re-initialization. The device configuration is now out-of-sync with the Manager settings and may be down. This can also occur when a failed device is replaced with a new unit, and the new unit is unable to discover its configuration information. Consult the system log for details.
Interface/Sub-Interface Creation Failure Error Device {0} could not generate an interface or sub-interface. This fault generally occurs in situations in which the port configuration is incorrect. For example, when a port pair is configured to run in different operating modes (1 is in-line mode while 2 is in SPAN mode). Reconfigure the physical port settings and consult the system log for details.
Deployment Failure Error The attempt by the Manager to deploy pending changes to device {0} failed. This could be due to a network connectivity issue. (The Manager will continue to attempt deployment until it is successful) Consult the system log for details.
Geolocation Database Deployment Failure Error Deployment of geolocation database to the device {0} by the Manager failed. This could be due to a network connectivity issue. If the problem persists, consult the system log for details.
Guest Portal Certificate Deployment Failure Error Deployment of guest portal certificate to the device {0} by the Manager failed. This could be due to a network connectivity issue. If the problem persists, consult the system log for details.
E-mail Server Unreachable Error The connection attempt to e-mail server {0} failed. Error: {1}. This fault occurs when the Manager fails to send an email notification or a scheduled report. Confirm connectivity with the server and that the proper ports are open.
Syslog Server Unreachable Error The connection attempt to syslog server {0} failed. Error: {1}. This fault occurs when the Manager fails to send a syslog notification. Confirm connectivity with the server and that the proper ports are open.
Alert Processing Error Error The Manager alert queue has reached its maximum size of {0} alerts. ({1} alerts dropped) Alerts are being received at a higher rate than the Manager can process. The Manager will not accept additional alerts until it is done processing the existing ones. Reduce the alert rate by tuning your IPS policies. For example, disable/remove informational alerts.
SNMP Notification Error Error The Manager's SNMP forwarder queue has reached its maximum size of {0} alerts. ({1} alerts dropped) Notifications are being sent at a higher rate than the Manager can process. The Manager will not send additional notifications until it is done sending the existing ones. Reduce the number of notifications sent by applying a more restrictive filter. For example, only send notifications for high-severity attacks or explicitly selected attacks.
Alert Processing Error Error The Manager has reached its limit ({0}) for alerts that can be queued for storage in the database. ({1} alerts dropped) Alerts are being received at a higher rate than the Manager can process. The Manager will not accept additional alerts until it is done processing the existing ones. Reduce the alert rate by tuning your IPS policies. For example, disable/remove informational attacks.
Packet Capture Processing Error Error The Manager packet capture queue has reached its maximum size of {0} packets captures. ({1} packet captures dropped) Packet captures are being received at a higher rate than the Manager can process. The Manager will not accept additional packet captures until it is done processing the existing ones. Reduce the packet capture rate by ensuring tuning your IPS policies. Tuning may achieved by reduing the number of attacks, such as informational alerts, as well as reducing the packet capturing per attack. For example, disable post-attack packet captures. Tip: Run the Manager Health Check to see which policies have one or more attack definition with post-attack packet capturing enabled.
Automatic Signature Set Download Error Error The Manager was unable to download the latest signature set from the Trellix IPS Update Server as scheduled. Error Message: {0}. Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.
Automatic Callback Detectors Download Error Error The Manager was unable to download the latest Callback Detectors from the Trellix IPS Update Server as scheduled. Error Message: {0}. Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.
Automatic Deployment Error Error The Manager was unable to deploy signature sets and configuration changes as scheduled. Error Message: {0}. Consult the system log for errors while generating the signature file (compilation errors, signature set validity or compatibility errors) and confirm connectivity between the Manager and its device.
Automatic Callback Detectors Deployment failure Error The Manager was unable to deploy Callback Detectors as scheduled. Error Message: {0}. Consult the system log for Callback Detector errors and confirm connectivity between the Manager and its device.
Incident Update Failure Error The Manager is unable to accept more incidents from the Incident Generator. Error message: {0}. Delete old incidents to make room for incoming incidents.
MDR Synchronization Error Error There was an error retrieving data from the peer Manager - aborting the synchronization process. Confirm connectivity between the Managers.
Alert Pruning Error Error The Manager was unable to prune alerts and attack packet captures during its routine maintenance. Error Message: {0}. Consult the database logs for errors and run the Manager Health Check to confirm the database is in good standing.
Too Many Virtual NTBA Appliances Error NTBA Appliance {0} could not be discovered because the supported number of virtual NTBA Appliances has already been reached. Remove the device.
Device Reboot Required Warning The jumbo frame parsing setting on this device has been updated and a reboot is required for the change to take effect. Reboot the device to make the change take effect.
MLC Server Connection Error Error Manager has no connection to configured MLC server. Confirm connectivity to the MLC server and that the correct MLC certificate has been imported into the Manager.
MLC Bulk Update File Size Exceeds Limit Error The Sensor has a limit for the MLC-Bulk-Update-File size that it can process. As this has exceeded, update to the Sensor is aborted. Check the MLC server configured in this Manager for the number of users, groups and IP user mappings. Make sure they do not exceed the limits specified in the MLC integration guide.
ePO Server Connection Error Error The Manager has no connection to configure ePO server {0}. Confirm connectivity between the devices and the credentials used for ePO integration.
NMS Authentication Key Decryption Error Error NMS user authentication key decryption failed for user "{0}". Delete and re-add the NMS user with valid credentials.
NMS Privacy Key Decryption Error Error NMS user privacy key decryption failed for user "{0}". Delete and re-add the NMS user with valid credentials.
CA-Signed Certificate Error Error Error: {0}.

Error: {0}. Certificate Fingerprint: {1}

Consult the system logs for details.