The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing rulesets

Prev Next

Rulesets are files that determine how the Sensor handles network traffic.

Tip

Administrators can provide custom rule files based on specific organizational security requirements.

You can manage the rulesets for Suricata Sensor in Ruleset tab. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.

The following ruleset file details are displayed:

Option

Definition

Ruleset Name

Name of the ruleset file.

Publisher Name

Name of the publisher of the ruleset file.

Ruleset File

Ruleset file name.

Ruleset Version

Version of ruleset file.

Imported By

Details of the ruleset file importer.

Imported Date

Last imported date in DD-MMM-YYYY format.

How to import, export, and delete ruleset files

You can import the suricata rules file from your Threat Content Provider into the IPS Manager, then deploy the file to the IPS Sensor.

Import ruleset files

Steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.

  2. Select Import from Manage Ruleset drop-down. The Import or Update Suricata Ruleset is displayed.

    Important

    The Manager only supports files with the .rules extension.

    1. Suricata Ruleset File: Click Browse and select the required ruleset file.

    2. Ruleset Name: Displays the name of the ruleset file.

    3. Publisher Name: Displays the publisher name.

  3. Click Import.

  4. The File Import Complete message displays after a successful import.

Export ruleset files

Steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.

  2. Select Export from Manage Ruleset drop-down. The existing ruleset file will be downloaded.

Delete ruleset files

Steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click Ruleset tab. The Ruleset tab is displayed.

  2. Select Delete from Manage Ruleset drop-down. A Warning window is displayed.

  3. Click Ok to delete the file.