The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Saving the Snort custom attacks

Prev Next

After you write or import the rules, you need to save them to the Manager database. Then, the rules for which the State is Published, are automatically added to the various exploit policies (both for inbound and outbound). This is similar to how the Trellix IPS custom rules are Published in the policies. Review the following points to understand how the rules are published in the policies.

The newly added or modified attacks are automatically compiled at the time of saving. The attacks that fail compilation are set to:

  • Failed in the Test Compile column

  • Staged in the State column

Only rules that comply with the following conditions qualify to be published in the exploit policies of Trellix IPS:

  • The Snort rule has been converted to Trellix IPS format successfully or with warnings.

  • The State is set to Published.

All the qualified rules are published in the Default Prevention policy. In addition, these rules are also published in other policies that meet the following criteria:

  • Benign Trigger Probability of medium. By default, all the imported Snort rules are assigned a Benign Trigger Probability value of medium which cannot be modified.

  • Severity of the attack. This depends on the default classification based on the classtype of a rule or the priority tag in the rule.

  • Protocol