The Signature Sets option enables you to download available attack signature updates on demand from the Update Server to the Manager server. You can then push the signature download onto your Sensors. You can also download the latest signature sets from an offline utility OfflineSigsetDownloader. For more information, see Offline Signature Set Downloader.
Tip
Because incremental emergency signature sets can be downloaded with regular signature sets, you do not need to use the custom attack definitions feature to import late-breaking attacks.
The Signature Sets option not only allows you to import regular signature sets, but also incremental emergency signature sets that include attack signatures not yet available in regular signature sets.
Incremental emergency signature sets are meant to address late-breaking attacks that might need to be addressed immediately.
Emergency signature sets are non-cumulative and can only add new signatures, so they do not contain a full set of signatures.
To make sure that you have a complete set of signatures, Trellix IPS verifies to see if a required regular signature set is missing and downloads it before downloading the related emergency signature set.
Note
You must use the Automatic Download option of Signature Sets tab from Manager → <Admin Domain Name> → Trellix IPS Protection Status for Trellix IPS to download a required regular signature set automatically, before downloading an emergency signature set. You receive an error if you try to import an emergency signature set through the Manual Import tab. For more information about Automatic Download, refer to Automatic download of Signature sets.
When a signature file or version is downloaded, the version is displayed in the Active Manager Version. Setting a schedule enables the Manager to verify the Update Server for signature updates on a periodic basis, download the available updates, and push these updates to your Sensors without your intervention.
Note
The signature set's major version (i.e, its first two digits) should be equal to or higher than the IPS Manager's major version (i.e, its first two digits) for it to be compatible with the Manager. Starting from 11.1 Update 2 or later, the Manager performs validation based on the signature set file's major version being equal to or higher than its major version and thus prevents the download or manual import of any incompatible signature set version that does not match the validation criteria.
For example, any Manager running on version 11.1 Update 2 supports the download and deployment of signature set version 11.9.x.x, but not signature set version 10.8.x.x or 9.8.x.x. In case of an incompatible signature set file download or its manual import, an error message is displayed on the Manager UI. You can find more details about the error from the ems.log file, or check for the same log entries on the Manager → <Admin Domain Name> → Troubleshooting → Logs → System Files tab.
Select Manager → <Admin Domain Name> → Trellix IPS Protection Status. Then, select Signature Sets tab. The Signature Sets tab is displayed.
The Active Manager Version displays currently available version for your Sensors.
The Latest Available Version displays the latest available version for your Sensors to download. This signature set is kept in a queue for download to your Sensors. You can only have one version in the queue for download.
Note
You can also change the display settings to meet your requirements from the filter option.
.jpg)
To download the latest signature set, select Download Latest Signature Set.
A Confirmation dialog box appears, select OK. A status window opens to process the signature download.
To download other versions of signature set, select Download Other Versions.
The Download Specific Signature Set dialog box appears, it displays the update details such as Release Date and Size (MB) for that particular Version.
Select the required version and click Download. A status window opens to process the signature download.
If the active manager version is the latest available version, Download Latest Signature Set is disabled.
A
icon is displayed beside the Active Manager Version if the active signature set version matches the latest signature set version.A
icon is displayed beside the Active Manager Version if the active signature set version is older than the latest signature set version.
Note
In an air-gap network, unregistered, or proxy server disabled Manager:
The Latest Available Version is displayed as ---.
A
icon is displayed beside the Active Manager Version.When you select Download Other Versions, the Download Specific Signature Set does not display the available versions of signature sets.
.jpg)