The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading the Sensor from 10.1 or 11.1 to 11.1.17.87

Prev Next

NS7600 20 Gbps licensing support

This 11.1 release now enables the NS7600 Sensor model to achieve 20 Gbps throughput. This significant performance upgrade is designed to support more demanding network environments. However, this enhanced 20 Gbps throughput does not apply when the Sensor is functioning in a failover pair.

IPS CLI enhancements:

The following Sensor CLI commands are updated:

Debug Mode

Command

Description

getnistats

Several counters have been added to identify specific errors and statistics related to exporting data to the Trellix Network Investigator (NI), such as the following:

  • Counters to track the Sensor's configuration polling requests to the NI device, including total requests, successes, failures, and specific errors like invalid tokens, timeouts, or gateway errors

  • Counters for the export of Netflow and Metadata, which include total POST requests, export successes and failures, various timeouts, and connection errors such as authentication failures or bad gateway responses

  • Counters that monitor the success and failure of creating the necessary Netflow and Metadata templates

  • Counters for the Sensor's internal data handling, including memory map (memmap) enqueue success and failure, discarded messages, and errors related to invalid data or system function failures

ninetflowstat

Some of the counters that have been added are the following:

  • Counters to track the lifecycle of memory buffers (mbufs) used for Netflow and Metadata, including successful allocations, frees, and their corresponding failures

  • Count of total Netflows and Metadata ring enqueue failures from l7ae to NI

  • Counters for other issues, such as Total Netflow send failed and Total Metadata invalid event type.