Trellix Snort engine is the existing Snort engine available in Trellix IPS that performs attack detection. With release 10.1, you can use Suricata Snort engine as well. The Suricata Snort engine provides a dedicated Snort environment which supports most of the third-party Snort constructs that are available in the public domain. This allows you to import most of the custom and third-party Snort rules without modification.
To enable the preferred Snort engine at the admin domain level, go to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings.
To enable the preferred Snort engine at device level, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Advanced Device Settings.
The Advanced Device Settings page at the global and device levels allow you to select the Snort engine you prefer to use.
Note
Trellix Snort engine is selected by default.
For more information on the supported constructs, see Trellix Intrusion Prevention System Product Guide.