The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager warning faults

Prev Next

These are the warning faults for a Manager and Central Manager.

Fault Severity Description/Cause Action
GTI URL Reputation Services Disabled Warning The Manager has disabled the GTI URL reputation services on device {0} because one or more prerequisite has not been met. The Manager must have telemetry enabled for alert data details (unless using a private GTI cloud), and name resolution must be enabled on the device. Enable telemetry and name resolution. Re-deploy the changes to the device.
Alert Storage Capacity Threshold Warning Warning Alert capacity: {0}. Current alert count: {1}. Prune and tune the database.
Database Size Warning Warning Current database size: {1} GB. Disk capacity: {0}. Prune and tune the database.
Automatic Database Backup Error Warning The Manager was unable to back up its database as scheduled. Error Message: {0} Check available disk space and that the necessary permissions to the directory have been given to the Manager application.
Pending License Expiration Warning Your license is going to expire in less than 7 days. Replace expiring licenses.
Ungraceful Manager Shutdown Warning The Manager service was not shut down gracefully. Tune the database to fix any errors caused by the previous shutdown. To ensure a graceful shutdown, explicitly stop the Manager service before shutting down the host on which it is running.
Deprecated Application Detected in Firewall Policies Warning The Manager has detected the following use of deprecated applications in firewall policies: {0} Remove these applications from firewall policies.
Missing Syslog Server Warning Firewall logging has been enabled, yet no syslog server is currently defined/enabled for admin domain {0}. Define and enable a syslog server for forwarding firewall access events.
Database Tuning Recommended Warning {0} days have passed since the last database tuning. Tune the database.
Automated MDR Switchover Detected Warning An automatic MDR switchover has completed without error. (The secondary {0} will take control of the {1}.) Check the MDR log and the Manager system log on both Managers to understand if the primary is down or simply disconnected from the secondary.
MDR - {0} Version Mismatch (current {1} has newer version) Warning The two {0}s in an MDR configuration must have the same {0} software version installed. The current {0} server software is more recent than that of the peer {0}. Ensure both Managers are running the same Manager software version.
MDR - {0} Version Mismatch (peer {1} has newer version) Warning The two {0}s in an MDR configuration must have the same {0} software version installed. The peer {0} server software is more recent than that of the current {0}. Ensure both Managers are running the same Manager software version.
MDR - Manager Type Mismatch Warning The two Managers in an MDR pair must be of the same type (Manager versus Central Manager). Ensure both Managers are of same Type (Trellix IPS Central Manager versusTrellix IPS Manager).
MDR - Invalid Request Warning The {0} request is not from a trusted IP address. Ensure the Peer Manager is not already in MDR with another Manager.
MDR - Device-to-Manager IP Mismatch Warning The device-to-Manager communication IP {0} does not match with the peer Manager IP {1}. Ensure the Device-to-Manager communication IP matches with the peer Manager peer IP in the MDR configuration.
MDR - IPv4 and IPv6 Address Warning Warning You have specified only the peer Manager {0} address. So you cannot add any {1} devices to the current Manager, nor will the existing {2} devices be able to communicate to the peer Manager. If devices need to communicate with the Manager over IPv6 and the Manager is part of an MDR Pair, MDR must be reconfigured to include the IPv6 address of the peer Manager.
Internet Connectivity Required for Trellix Virtual IPS Cluster Usage Warning Trellix Virtual IPS cluster usage data must be sent to Trellix for proper Trellix Virtual IPS Cluster function, however, this Manager is currently unable to send the usage data to Trellix. Deployment of pending changes to Trellix Virtual IPS Clusters will be prevented until connectivity has been restored. Tip: The Manager will automatically attempt to contact Trellix again in one hour. If you believe connectivity has been restored sooner, use the Test Connection button on the GTI Integration page to confirm and reset the ability to deploy pending changes. Check Internet connectivity, including proxy settings and name resolution.
License Required for Trellix Virtual IPS Sensor/Probe Warning A valid license is required to manage Trellix Virtual IPS Sensors/Probes, however, no license currently exists on the Manager. Without at least one license, deployment of pending changes to Trellix Virtual IPS Sensors will be prevented. Add a license.
Scheduled Reports Error Warning Report generation failed for report template {0} because one or more of the selected resources in its definition is no longer available. Edit and save the updated template.
Manager Deleted Warning The Manager information {0} has been deleted. Reason: {1}. View related-faults and consult the system log for details.
Policy Synchronization Terminated Warning Policy synchronization has been terminated because concurrent processes are running on the Manager. Consult the background tasks log to view running tasks and try again.
Deleted Trellix IPS Central Manager Policy in Use Warning Policy {0} is currently assigned to one or more resource. Creating copy {1} before deletion.
DeletedTrellix IPS Central Manager Attack Filter in Use Warning Attack filter {0} is currently assigned to one or more resource. Creating copy {1} before deletion.
Deleted Trellix IPS Central Manager Attack Set Profile in Use Warning Attack set profile {0} is currently assigned to one or more resource. Creating copy {1} before deletion.
IPS Policy Backup Error Warning Failed to back up policy {0}. Consult the system log for details.
IPS Policy Backup Error Warning Failed to back up policy {0}. The maximum limit of {1} has been reached. Delete previous backups.
Reconnaissance Policy Backup Error Warning Failed to back up policy {0}. Consult the system log for details.
Reconnaissance Policy Backup Error Warning Failed to back up policy {0}. The maximum limit of {1} has been reached. Delete previous backups.
MLC IP-User Mapping Count Exceeds Limit Warning Currently, Trellix IPS Manager-MLC integration supports only 100,000 IP-user mapping.This has exceeded, so the Sensor behavior cannot be guaranteed until these numbers are brought down. Consider reducing the number of computers MLC is monitoring.
MLC User Count Exceeds Limit Warning Currently, Trellix IPS Manager-MLC integration supports only 75,000 users. This has exceeded, so the Sensor behavior cannot be guaranteed until these numbers are brought down. Consider reducing the number of users MLC is monitoring.
MLC Bulk Update File Transfer Error Warning MLC bulk update failed on sensor {0}. There is no explicit action required. The Manager will retry to send the bulk update again automatically.
Policy Update Error Warning Failed to update policy "{0}" during signature set import. Edit the policy to fix the issue.
Invalid Malware File Archive Storage Settings Warning The available free disk space on the Manager ({0}) is less than the disk space required to support the current malware storage settings ({1}). Reduce the maximum disk space allowed for one or more file type.
Non-MVM Vulnerability Report Import Error Warning {0} Confirm the existence of the file and its format.
Non-MVM Vulnerability Report Import Complete with Warnings Warning {0} If the timestamp on the newly-imported report is the same as or older than the previously imported report, confirm that your process to copy new report files to the Manager file system is functioning properly.
MDR - Manager {0} Switched from {1} to {2} Mode Warning

Manager {0} is taking the control.

The Manager "{0}" is "{1}" and its peer Manager, "{2}" is "{3}.