The Snort rules or User-Defined Signatures (UDS) that you create or import, must be compatible with the Trellix IPS signature set. When you save the custom attacks in the Custom Attack Editor, the Manager validates the rules to check their compatibility. If there are any incompatible custom attacks, a critical system fault message Incompatible custom attack is raised as a system fault. You can view the system faults in the Manager → <Admin Domain Name> → Troubleshooting → Logs page. After you correct the incompatible custom attacks, you can use Test Compile to verify the compatibility of the rules before you save them. For subsequent signature set updates, only attacks that pass compilation are published to the Sensors.
Consider the following when running Test Compile:
Running Test Compile does not change the compilation status of attacks. The compilation status of attacks is updated only after you save the attacks. After you save, attacks that fail compilation are marked as Failed in the Test Compile column and will be in Staged state.
For information on rules that determine the state of the attack, see Rules for determining the value of the State.
You need to select the attacks that should be compiled.
Attacks only in the Published state can be compiled. As an exception, if all the selected attacks are in Staged state, the attacks are compiled.
Attacks that fail the test compilation are not highlighted by the Manager. To identify the specific attacks that fail, you can run Test Compile on a subset of attacks and verify if they fail. You can continue this process of elimination until you identify the specific attacks that fail.
For example, select 10 attacks for test compilation and compilation reports a failure. To identify the specific attacks that failed, select a subset of attacks from the initial 10 attacks and run test compilation. If test compilation still reports failure, repeat the process of elimination until you find the specific attacks that fail.
Attacks from the Central Manager are not considered for test compile in the Manager.
Note
The Manager compiles all the active custom attacks during reboot or startup. The IPS page is not available till the Manager finishes compilation. It takes about 7 minutes for the page to load.
Steps:
In the Custom Attack Editor, select the custom attacks you want to run a test compilation on.
Select Other Actions → Test Compile.
This option is available as part of the right-click menu.