Over the course of time, you will become very familiar with your Trellix IPS alert data as you perform forensic analysis using the Attack Log. At some point, you may even become tired of seeing some of the same alerts time and again. Trellix IPS provides multiple options for suppressing alerts, that is, reducing the number of alerts in either the Attack Log and/or database, so that you can work on your higher priority issues.
The following alert suppression options are available using various actions within the Manager interface:
- Disable alerting — During policy creation/modification, you can disable the alert for one or more attacks. This is not attack detection disabling, just alert disabling. The Sensor still detects the attack and can send an automatic response, if configured. (If no response is configured, nothing is done when the attack is detected.)
- Auto Acknowledge — Also during policy creation, you have the option of automatically acknowledging a detected attack. The Auto-Acknowledge feature suppresses the alert from the Attack Log by marking the alert as acknowledged. You can also create new auto acknowledgement rules for the alerts.
- Alert throttling — Alert throttling (seen as
Alerting Options in the Manager interface) enables you to set a suppression limit for a singular Exploit attack, which originates from one attacker, targets a single destination IP, and is detected by the same VIPS (interface or sub-interface) multiple times within a limited time frame. Exploit throttling limits the number of duplicate alerts that are sent to the Manager from a Sensor. Throttling is very effective against repetitive Exploit attacks where a attacker IP address is spoofed and generates a high number of alerts.
For more details, refer to Configure alert suppression with packet log response topic in IPS Administration section.
| Send alert to Manager | Send Sensor response action | Display alert in Attack Log | |
|---|---|---|---|
| Normal behavior | Yes | Yes | Yes |
| Detection on, disable alerting | No | Yes | No |
| Auto acknowledge | Yes | Yes | Yes/No (depending on the column view in Attack Log) |
| Alert throttling | Yes | Yes | Yes |