The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule options section

Prev Next

The rule options section is the more critical section of a Snort rule. The rule options are to be separated by a semicolon. In a rule option, the keyword and argument are separated by a colon.

Rule options fall into one of the following categories:

  • General: These options contain the metadata for the rule but have no effect on attack detection.

  • Payload: These options look for data inside the packet payload and can be interrelated.

  • Non-payload: These options look for non-payload data.

  • Post-detection: These options indicate what happens when an attack is detected. These options are not relevant in Trellix IPS. Instead, you can configure the response actions in the IPS Policy Editor.