The action specifies how the Sensor should respond when it detects traffic as defined in the rule. In Trellix IPS, the only action that you can specify in a Snort rule is to send an alert to the Manager. The procedure to configure other response actions such as packet log and packet drop is the same as that of the regular Trellix IPS attacks. That is, use the IPS Policy Editor to configure these actions.
Rule action
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?