The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Synchronizing ignore rules

Prev Next

Ignore rules created in the Central Manager are synchronized with all the managers added to that Central Manager. In Central Manager, synchronization can be run manually (either as incremental or as full) or as scheduled. Ignore rules created in the Central Manager are pushed to the parent admin domains of individual Managers added to the Central Manager and are eventually applied to all levels such as admin domains, Sensors, and interfaces.

When you create an ignore rule from Central Manager Attack Log, it is effectively created and managed by the target Manager where the alert belongs. The target Manager user can edit or maintain that rule; however, rules and corresponding objects created on the Ignore Rules page of the Central Manager are created and managed by the Central Manager. Such rules are shown in read-only mode on the applicable Managers and exposed with an "owner of NSCM" name. This is because the Manager or admin domain is not the owner in this case.

You can use an ignore rule created at the Central Manager in the Manager. The ignore rules are pre-fixed with "NSCM" to distinguish between the ignore rules present in the Manager and the Central Manager. You cannot associate ignore rules at the Central Manager. However you can associate ignore rules created at Central Manager to Sensors at the Manager. You can export and import associated ignore rules from the Manager.

Note

  • You cannot delete an ignore rule created by the Central Manager from the Manager.

  • Ignore rules created at the Central Manager cannot be exported.

What happens to the synchronized ignore rules when communication between the Central Manager and the Manager is dissolved?

If the Manager uses an ignore rule created at the Central Manager, then the ignore rule is cloned and retained in the Manager as an ignore rule with an "NSCM" prefix. Even if the Manager has not used any of the synchronized ignore rules, they are retained in the Manager.

The key to synchronization of Central Manager rules objects and ignore rules with their respective local Manager is the object's name. For example, imagine that an ignore rule called "IG Rule A" is created in the Central Manager which is later synchronized with Managers. On the Managers' side, you will see the same ignore rule as "NSCM IG Rule A." These ignore rules synchronized from Central Manager are not editable but clonable.