The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Suppressing alerts

Prev Next

Over the course of time, you will become very familiar with your Trellix IPS alert data as you perform forensic analysis using the Attack Log. At some point, you may even become tired of seeing some of the same alerts time and again. Trellix IPS provides multiple options for suppressing alerts, that is, reducing the number of alerts in either the Attack Log and/or database, so that you can work on your higher priority issues.

The following alert suppression options are available using various actions within the Manager interface:

  • Disable alerting — During policy creation/modification, you can disable the alert for one or more attacks. This is not attack detection disabling, just alert disabling. The Sensor still detects the attack and can send an automatic response, if configured. (If no response is configured, nothing is done when the attack is detected.)

  • Auto Acknowledge — Also during policy creation, you have the option of automatically acknowledging a detected attack. The Auto-Acknowledge feature suppresses the alert from the Attack Log by marking the alert as acknowledged. You can also create new auto acknowledgement rules for the alerts.

  • Alert throttling — Alert throttling (seen as Alerting Options in the Manager interface) enables you to set a suppression limit for a singular Exploit attack, which originates from one attacker, targets a single destination IP, and is detected by the same VIPS (interface or sub-interface) multiple times within a limited time frame. Exploit throttling limits the number of duplicate alerts that are sent to the Manager from a Sensor. Throttling is very effective against repetitive Exploit attacks where a attacker IP address is spoofed and generates a high number of alerts.

    For more details, refer to Configure alert suppression with packet log response topic in IPS Administration section.

Send alert to Manager

Send Sensor response action

Display alert in Attack Log

Normal behavior

Yes

Yes

Yes

Detection on, disable alerting

No

Yes

No

Auto acknowledge

Yes

Yes

Yes/No (depending on the column view in Attack Log)

Alert throttling

Yes

Yes

Yes