Your policy determines what traffic analysis your Sensor will perform. Trellix IPS provides a number of policy templates to get you started toward your ultimate goal — prevent attacks from damaging your network, and limit the alerts displayed in the Attack Log page to those which are valid and useful for your analysis.
There are two stages to this process — initial policy configuration and policy tuning. Though these are tedious tasks, Trellix has extended its blocking options to include SmartBlocking, which only activates blocking when high confidence signatures are matched, thus minimizing the possibility of false positives. Trellix IPS is replacing its present Recommended for Blocking (RFB) designation with Recommended for SmartBlocking (RFSB) because this new level of granularity enables Trellix to recommend many more attacks – the list of RFB attacks is a subset of the list of RFSB attacks.
The ultimate goal of policy tuning is to eliminate false positives and noise, and avoid overwhelming quantities of legitimate, but anticipated alerts.