The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor latency monitor management

Prev Next

All networks working from layer 2 through layer 7 experience some amount of latency. Latency monitor provides a means to reduce latency introduced by the Sensor, when the amount of traffic seen on the network substantially exceeds the Sensor capacity. Sensor latency can be due to various factors such as the policies configured, protocols, content, applications, type of traffic flowing through the Sensor, and so on. The Inspection Options Policies configured also adds to the latency. The following features consume Sensor resources which results in latency:

  • HTTP Response Traffic Scanning

  • Traffic Inspection

  • Callback Activity

  • Advanced Malware Policies

  • SSL decryption

The latency can be reduced or varied, if Sensors detect the latency condition. Whenever there is a latency in the network, the Sensor performs the following functions:

  • Raises an alert in the Manager whenever there is a latency in processing the packets

  • Mitigates latency by switching to layer 2 mode

Latency monitor is available in all NS-series Sensor models.

Latency monitor feature configured monitors the time consumed for processing the packets. If the number of packets exceeds the threshold for which processing time is high, it is considered as a condition of latency. You can configure latency monitor as alert-only mode or layer 2 mode. When latency is detected, based on the configuration, an alert is raised in the Manager for the alert-only mode. If it is configured for mitigation, the latency is mitigated before an alert is raised in the Manager.

Latency monitor feature is disabled by default. The feature has to be enabled only when there is latency in the network introduced by the Sensor. If the feature is kept enabled, there is a possibility of some attacks not being detected by the Sensor.

To mitigate latency, the Sensor switches to layer 2 mode based on the sensitivity level configured. This takes less than a second after latency is detected. After latency is mitigated, the Sensor switches back to inline mode, depending on the time configured using the CLI command latency-monitor restore-inline. For example, if the latency-monitor restore-inline command is configured for 10 minutes, the Sensor tries to switch back to online mode (from layer 2) after 10 minutes.

Note

If the Sensor is not configured to return to inline mode automatically, it has to be manually restored to inline mode from layer 2 mode using the CLI command latency-monitor restore-inline.

Trellix IPS provides latency monitoring at three different sensitivity levels. The sensitivity levels configured in latency monitor checks for latency in two different stages:

Stage 1

  • High sensitivity — Checks for latency in every incoming packet before processing

  • Medium sensitivity — Checks for latency in every alternate packet before processing

  • Low sensitivity — Does not check for latency

In the above scenarios, if latency is not detected, the packets are forwarded for further processing to stage 2.

Stage 2

Once latency is detected, the packets are processed through multiple phases taking optimized measures internally to handle high latency. If latency is mitigated by this process, the Sensor returns to normal processing. If latency is not mitigated, the Sensor switches to layer 2 mode if configured.

The time consumed for processing each packet is calculated when the packet is being processed by the Sensor. The calculations are based on the following parameters:

  • Number of packets for which the latency is high

  • Duration for which this latency condition persists

This duration for which the latency condition is monitored depends on the configured sensitivity level. Latency is detected based on the following sensitivity level thresholds configured:

  • High latency — If latency is experienced (high) for 1/6th of a second for every 50 packets

  • Medium latency – If latency is experienced for 2/6th of a second for every 100 packets

  • Low latency – If latency is experienced (persists) for 3/6th of a second for every 150 packets

When latency is detected, the Sensor switches to latency management mode trying to mitigate latency by optimizing processes. During this mode, the situation is continuously monitored to check if the latency is mitigated. Optimization of processes may include turning off the attack detection and packets being forwarded without attack detection. The Sensor switches to layer 2 mode, if enabled, when latency is not mitigated even after running the optimization processes.

The following CLI commands for Oversubscription are deprecated:

  • set oversubscription enable

  • set oversubscription disable

  • show oversubscription status

Trellix recommends that you use latency monitoring instead.