The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor error faults

Prev Next

Fault

Severity

Description/Cause

Action

Suricata Config Deployment Failure

Error

Deployment of Suricata Config to the device <Device Name> by the Manager failed. There could be a connectivity issue between Manager and device. Fail reason: TFTP Failed Result: Failure in sending snmp message (file ready) to sensor - sensor probably down/disconnected. Request fails, problem code is WRITE_FAILED and explanation is As the request was being written out the write failed

To resolve this failure, kindly retry Suricata Config deploy to this sensor from the Device Manager page. If the problem persists, consult the system log for details.

Firewall Filter Application Error

Error

Error applying firewall filter "{0}." An attempt to apply this firewall filter from the device to the firewall has failed. Failure reason: {1}.

Check your firewall configuration. If possible, increase the maximum number of available filters. Ensure connectivity between the device and the firewall.

NMS User Authentication Key Decryption Failure

Error

NMS user authentication key decryption failed for {0}

Delete and re-add the NMS user.

NMS User Privacy Key Decryption Failure

Error

NMS user privacy key decryption failed for {0}

Delete and re-add the NMS user.

SSL Decryption Engine Down

Error

The SSL decryption service is down on the device {0}. HTTPS traffic cannot be inspected.

Check the device logs for additional details and contact Trellix Technical Support if it persists.

SSL Decryption Update Error

Error

The SSL decryption configuration update failed for component {0}

Check the device status using the "status" CLI command and re-attempt to deploy the changes from the Manager.

Internal Packet Drop Error

Error

The device is dropping packets due to high traffic load.

Review the number and duration of performance-related faults for this device and refer its performance charts to determine if high usage is an on-going occurrence. If yes, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity)

IPS to NTBA Communication Error

Error

The IPS device cannot communicate with its NTBA appliance. Reason: {0}

This problem may exist for a few minutes after the initial connection but is cleared once complete. If the problem persists, check for interference from external devices, such as a firewall that may be dropping the traffic.

Cannot Start Control Channel Service

Error

Cannot obtain the Manager certificate (Size {0}).

Database tuning may fix the problem. Else, a database restore is required.

Cannot Start Control Channel Service

Error

Unable to load the Manager key store.

Database tuning may fix this problem. Else, a database restore is required.

Failed to Create Command Channel Association

Error

Command channel association creation failed for device {0}. A secure connection could not be established between the Manager and the device. This could be caused due to loss of time during synchronization between the Manager and device, or when the device is not completely online after a reboot.

Restart the Manager and/or check the device status to ensure that the device is connected to the Manager and in good health.

{0} Discovery Failure

Error

{0}, {1} failed to discover configuration information. The device is not initialized properly and may not be displayed in the Manager UI. This error is typically due to incompatible software versions between the device and the Manager.

Check the Trellix Download Portal to ensure you are running compatible Manager and device software versions. If required, upgrade the device software via SCP or TFTP.

Peer DoS Profile Retrieval Failure

Error

Peer DoS profile retrieval request from device {0} failed. No DoS profile for peer {1} is available. The Manager cannot obtain the requested profile from the peer device, nor can it obtain a valid saved profile.

Consult the system log for details.

Peer DoS Profile Retrieval Failure

Error

Peer DoS profile retrieval request from device {0} failed as the profile cannot be pushed from the Manager to the device that requested it.

Consult the system log for details.

Invalid Internal Web Server Certificate Detected

Error

An invalid internal web server certificate ({0}) has been detected on device {1} and needs to be re-imported. Reason: {2}

Re-import the internal web server certificate.

Device Discovery Failure

Error

The Manager could not obtain configuration details for device {0}. The device is not properly initialized and may not be displayed in the Manager UI. This error is typically due to incompatible software versions between the device and the Manager.

Check the Trellix Download Portal to ensure you are running compatible Manager and device software versions. If required, upgrade the device software via SCP or TFTP.

Alert Channel Down

Error

The Manager cannot communicate with the device {0} over the channel on which it receives alerts. Reason: {1}.

Check the device status using the "status" CLI command. Disconnect and re-connect the channel using the "disconnectalertandpktlogchannels" and "reconnectalertandpktlogchannels" CLI commands.

Packet Capture Channel Down

Error

The Manager cannot communicate with the device {0} over the channel on which it receives the attack packet captures. Reason: {1}.

Check the device status using the "status" CLI command. Disconnect and re-connect the channel using the "disconnectalertandpktlogchannels" and "reconnectalertandpktlogchannels" CLI commands.

Packet Capture Channel Down

Error

The packet capture channel for the device {0} is down, but the physical link is up. Details: {1}

The device normally auto recovers from this issue. If your device is otherwise functioning normally, you can ignore this message.

Out-of-Range Configuration

Error

Device {0} has detected an out-of-range SNMP configuration value.

If the problem persists, contact Trellix Technical Support.

License Required for SSL Proxy Decryption

Error

Sensor {0} was added to admin domain {1}, which has SSL proxy decryption enabled, yet there is no SSL proxy decryption license available for its model type {2}. Inheritance and the feature have therefore been disabled on Sensor {0}.

Add the missing license and re-enable SSL proxy decryption on the Sensor.

Trust Establishment Error

Error

Device {0} could not be added to the Manager as there is mismatch in the shared secret defined in the Manager.

Make sure the shared secret entered on the device CLI matches exactly with the one defined within the Manager GUI. (Tip: You can edit the one in the GUI if needed)

Trust Establishment Error

Error

Device {0} is attempting to establish a trust with the Manager, but it has not been defined on the Manager.

Make sure the device you would like to add to the Manager has been defined within the Manager GUI before trying to add it via the device CLI. Tip: The Manager definition is case sensitive, so make sure the device name and shared secret key match exactly.

SSL Decryption Certificate File Update Error

Error

The SSL certificate with key ID "{0}" error in "{1}".

Re-deploy the certificate file.

Suricata Rule Load Failure

Error

Device "{0}" failed to load one or more Suricata Snort rule. A log for this has been created in: INSTALL_DIR/App/temp/ftpin/{0}/{1}.

Consult the log for failure details.

Packet Capture Error

Error

The device detected an error connecting to the SCP server while attempting to transfer a packet capture file.

The device is unable to send the packet capture file via SCP.

The device has stopped capturing packets due to insufficient internal memory.

The device experienced an internal error while performing the packet capture.

The device is unable to authenticate with the target server to transfer the packet capture file.

The device will attempt to recover automatically. Confirm the packet capture configuration.

GAM Engine Update Status

Error

Sensor {0} has a status of: {1}.

Please check the connectivity of the Trellix IPS sensor with external network. If connection is fine, please attempt a manual GAM update from the Trellix IPS Manager. If the issue still persists, please contact the support team.

PKCS cert processing error

Error

Device {0} faced an error while processing the pkcs cert store.

Consult the system logs for details.

Process device information message failure upon new software import

Error

Processing of device information message has failed upon new software import. This issue will have impact in signature set deployment to Sensor and might cause additional unexpected failures.

Check device_config.log for details.

Process device information message failure upon Sensor connect

Error

Processing of device information message has failed upon Sensor connect. This issue will have impact in signature set deployment to sensor and might cause additional unexpected failures.

Check device_config.log for details.