The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule action

Prev Next

The action specifies how the Sensor should respond when it detects traffic as defined in the rule. In Trellix IPS, the only action that you can specify in a Snort rule is to send an alert to the Manager. The procedure to configure other response actions such as packet log and packet drop is the same as that of the regular Trellix IPS attacks. That is, use the IPS Policy Editor to configure these actions.