The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager error faults

Prev Next

These are the error faults for a Manager and Central Manager.

Fault

Severity

Description/Cause

Action

GAM Updating Error

Error

Device is detecting an error on av-dat file segment {0}. The segment error cause is {2}, and the download type is {3}. (The Manager will automatically make another attempt to deploy the update to the device.)

Ensure the device is connected to the Manager and in good health.

Deployment Failure

Error

The attempt by the Manager to deploy changes to device {0} failed during device re-initialization. The device configuration is now out-of-sync with the Manager settings and may be down. This can also occur when a failed device is replaced with a new unit, and the new unit is unable to discover its configuration information.

Consult the system log for details.

Interface/Sub-Interface Creation Failure

Error

Device {0} could not generate an interface or sub-interface. This fault generally occurs in situations in which the port configuration is incorrect. For example, when a port pair is configured to run in different operating modes (1 is in-line mode while 2 is in SPAN mode).

Reconfigure the physical port settings and consult the system log for details.

Deployment Failure

Error

The attempt by the Manager to deploy pending changes to device {0} failed. This could be due to a network connectivity issue. (The Manager will continue to attempt deployment until it is successful)

Consult the system log for details.

Geolocation Database Deployment Failure

Error

Deployment of geolocation database to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

Guest Portal Certificate Deployment Failure

Error

Deployment of guest portal certificate to the device {0} by the Manager failed. This could be due to a network connectivity issue.

If the problem persists, consult the system log for details.

E-mail Server Unreachable

Error

The connection attempt to e-mail server {0} failed. Error: {1}. This fault occurs when the Manager fails to send an email notification or a scheduled report.

Confirm connectivity with the server and that the proper ports are open.

Syslog Server Unreachable

Error

The connection attempt to syslog server {0} failed. Error: {1}. This fault occurs when the Manager fails to send a syslog notification.

Confirm connectivity with the server and that the proper ports are open.

Alert Processing Error

Error

The Manager alert queue has reached its maximum size of {0} alerts. ({1} alerts dropped) Alerts are being received at a higher rate than the Manager can process. The Manager will not accept additional alerts until it is done processing the existing ones.

Reduce the alert rate by tuning your IPS policies. For example, disable/remove informational alerts.

SNMP Notification Error

Error

The Manager's SNMP forwarder queue has reached its maximum size of {0} alerts. ({1} alerts dropped) Notifications are being sent at a higher rate than the Manager can process. The Manager will not send additional notifications until it is done sending the existing ones.

Reduce the number of notifications sent by applying a more restrictive filter. For example, only send notifications for high-severity attacks or explicitly selected attacks.

Alert Processing Error

Error

The Manager has reached its limit ({0}) for alerts that can be queued for storage in the database. ({1} alerts dropped) Alerts are being received at a higher rate than the Manager can process. The Manager will not accept additional alerts until it is done processing the existing ones.

Reduce the alert rate by tuning your IPS policies. For example, disable/remove informational attacks.

Packet Capture Processing Error

Error

The Manager packet capture queue has reached its maximum size of {0} packets captures. ({1} packet captures dropped) Packet captures are being received at a higher rate than the Manager can process. The Manager will not accept additional packet captures until it is done processing the existing ones.

Reduce the packet capture rate by ensuring tuning your IPS policies. Tuning may achieved by reduing the number of attacks, such as informational alerts, as well as reducing the packet capturing per attack. For example, disable post-attack packet captures. Tip: Run the Manager Health Check to see which policies have one or more attack definition with post-attack packet capturing enabled.

Automatic Signature Set Download Error

Error

The Manager was unable to download the latest signature set from the Trellix IPS Update Server as scheduled. Error Message: {0}.

Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.

Automatic Callback Detectors Download Error

Error

The Manager was unable to download the latest Callback Detectors from the Trellix IPS Update Server as scheduled. Error Message: {0}.

Consult the system log for details and confirm that the Manager can resolve names and communicate with its default gateway and proxy server, as applicable.

Automatic Deployment Error

Error

The Manager was unable to deploy signature sets and configuration changes as scheduled. Error Message: {0}.

Consult the system log for errors while generating the signature file (compilation errors, signature set validity or compatibility errors) and confirm connectivity between the Manager and its device.

Automatic Callback Detectors Deployment failure

Error

The Manager was unable to deploy Callback Detectors as scheduled. Error Message: {0}.

Consult the system log for Callback Detector errors and confirm connectivity between the Manager and its device.

Incident Update Failure

Error

The Manager is unable to accept more incidents from the Incident Generator. Error message: {0}.

Delete old incidents to make room for incoming incidents.

MDR Synchronization Error

Error

There was an error retrieving data from the peer Manager - aborting the synchronization process.

Confirm SSL (TCP 443) connectivity between the Managers (in both directions). If the secondary Manager is online, review its logs (both Manager and OS) for errors that might be preventing it from receiving the data transfer.

Alert Pruning Error

Error

The Manager was unable to prune alerts and attack packet captures during its routine maintenance. Error Message: {0}.

Consult the database logs for errors and run the Manager Health Check to confirm the database is in good standing.

Too Many Virtual NTBA Appliances

Error

NTBA Appliance {0} could not be discovered because the supported number of virtual NTBA Appliances has already been reached.

Remove the device.

TLC Server Connection Error

Error

Manager has no connection to configured TLC server.

Confirm connectivity to the TLC server and that the correct TLC certificate has been imported into the Manager.

TLC Bulk Update File Size Exceeds Limit

Error

The Sensor has a limit for the TLC-Bulk-Update-File size that it can process. As this has exceeded, update to the Sensor is aborted.

Check the TLC server configured in this Manager for the number of users, groups and IP user mappings. Make sure they do not exceed the limits specified in the TLC integration guide.

ePO Server Connection Error

Error

The Manager has no connection to configure ePO server {0}.

Confirm connectivity between the devices and the credentials used for ePO integration.

NMS Authentication Key Decryption Error

Error

NMS user authentication key decryption failed for user "{0}".

Delete and re-add the NMS user with valid credentials.

NMS Privacy Key Decryption Error

Error

NMS user privacy key decryption failed for user "{0}".

Delete and re-add the NMS user with valid credentials.

CA-Signed Certificate Error

Error

Error: {0}.

Error: {0}. Certificate Fingerprint: {1}

Consult the system logs for details.

RuleObjects file Deployment Failure

Error

Deployment of RuleObjects file to the device {0} by the Manager failed. There could be a connectivity issue between Manager and device.

To resolve this failure, kindly perform a manual sigfile deploy to this Sensor from the Deploy Pending Changes page. If the problem persists, consult the system log for details.

Error while uploading daily telemetry data into Titan F telemetry server

Error

Telemetry data must be sent to Titan F telemetry server to help Trellix stay ahead of threats. However, the Manager is not able to upload data at the moment. Manager will re-attempt to upload the data in 5 minutes.

Check ems.log to know more about upload failure.

Error while uploading hourly telemetry data into Titan F telemetry server

Error

Telemetry data must be sent to Titan F telemetry server to help Trellix stay ahead of threats. However, the Manager is not able to upload data at the moment. Manager will re-attempt to upload the data in 5 minutes.

Check ems.log to know more about upload failure.

Error while uploading corporate telemetry data into Titan F telemetry server

Error

Telemetry data must be sent to Titan F telemetry server to help Trellix stay ahead of threats. However, the Manager is not able to upload data at the moment. Manager will re-attempt to upload the data in 5 minutes.

Check ems.log to know more about upload failure.

Error while uploading threat telemetry data into Titan F telemetry server

Error

Telemetry data must be sent to Titan F telemetry server to help Trellix stay ahead of threats. However, the Manager is not able to upload data at the moment. Manager will re-attempt to upload the data in 5 minutes.

Check ems.log to know more about upload failure.

Error while saving telemetry data into the Manager database

Error

Telemetry data saved in Manager database will be used by customers to check the historic data sent to Titan F telemetry server. Due to this error, Default-Telemetry (Trellix Titan F telemetry server) custom report will have data missing.

Check ems.log to know more about telemetry data save failure.

Threat Feed data file Deployment Error

Error

Deployment of Threat Feed data file to the device {0} by the Manager encountered an error. There could be a connectivity issue between Manager and device.

To resolve this failure, kindly retry the operation last tried. If the problem persists, check the system logs for details.