The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing YAML configurations

Prev Next

You can use YAML configuration files to define Default or Custom Sensor settings. This configuration manages how the Sensor interacts with various protocols and system resources.

Key configuration options

  • Packet capture: Enables the collection of network packets for forensic analysis.

  • Syslog settings: Configures the destination and format for system log alerts.

  • Protocol behavior: Defines how the engine parses and inspects specific network protocols.

How to import and export YAML files

Import YAML files

Prerequisites:

  • You must export the default YAML file to use as a template for creating and importing custom YAML files.

  • If the Suricata Sensor enters an operational state that is not ideal due to custom YAML misconfigurations, you can recover the Sensor by applying the default YAML configuration from the Manager. This action resets the Suricata Sensor YAML configurations to factory defaults.

Steps:

To export the file, do the following:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.

  2. Next, go to Manage YAML File, select Export and choose Default YAML File. The existing YAML file will be downloaded.

The YAML file is the parent file and contains references to additional child .config files. To import a YAML file with its associated configuration files, select a .zip file. The system supports the following configuration files:

  • Classification.config

  • References.config

  • Threshold.config

    Important

    Use only the following names for configuration files: classification.config, reference.config, and threshold.config. If you specify any other name, the Manager displays an error.

Steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.

  2. Select Custom from YAML File in YAML Configuration page.

  3. Select Import from Manage YAML File drop-down. The Import YAML File window is displayed.

    Important

    The Manager only supports files with the .yaml and .zip extensions.

  4. Click on Browse and select the required YAML file. Next, click Import.

  5. The File Import Complete message displays after a successful import.

The Manager will store the .yaml and .config file content inside iv_suricata_yaml_files table.

Export YAML files

Steps:

  1. Go to Policy → <Admin Domain Name> → Intrusion Prevention → Suricata Configuration and click YAML Configuration tab. The YAML Configuration tab is displayed.

  2. Next, go to Manage YAML File and select Export. Choose Default YAML File or Custom YAML File based on your requirement.

    The selected YAML file will be downloaded.