The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Reduce false positives

Prev Next

Your policy determines what traffic analysis your Sensor will perform. Trellix IPS provides a number of policy templates to get you started toward your ultimate goal — prevent attacks from damaging your network, and limit the alerts displayed in the Attack Log page to those which are valid and useful for your analysis.

There are two stages to this process — initial policy configuration and policy tuning. Though these are tedious tasks, Trellix has extended its blocking options to include SmartBlocking, which only activates blocking when high confidence signatures are matched, thus minimizing the possibility of false positives. Trellix IPS is replacing its present Recommended for Blocking (RFB) designation with Recommended for SmartBlocking (RFSB) because this new level of granularity enables Trellix to recommend many more attacks – the list of RFB attacks is a subset of the list of RFSB attacks.

The ultimate goal of policy tuning is to eliminate false positives and noise, and avoid overwhelming quantities of legitimate, but anticipated alerts.