The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing ignore rules

Prev Next

When a particular alert is declared as a false positive, the next decision is whether to disable the corresponding attack altogether or, apply a particular ignore rule to that attack which will disable alerting for a particular IP address or range of IP addresses. In almost all cases, it is a best practice to implement the latter.

Consider some of the traffic in your network might appear as an attack. You are aware of the purpose of this traffic and you do not want the Sensor to take any response action on this traffic. However, if similar traffic is generated by any other server, you want the Sensor to treat it as an attack and respond accordingly. Trellix IPS provides various options to handle such situations.

Every ignore rule created is globally stored, so that the filter can be applied to any Exploit or Reconnaissance attack.

It is also a best practice to document all your tuning activities. The Configuration Report section can be used to assist the documentation process. The Performance Monitoring - Sensor Configuration report will deliver reports that list ignore rules that have been applied and attacks that have been otherwise customized.

Note

For more information, see the chapter How to create Ignore rules for an applied IPS policy in the Trellix Intrusion Prevention System Product Guide.