Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
The Trellix IPS documentation set is designed to provide you with the information you need during each phase of the product implementation from evaluating a new product to maintaining existing ones. After the product is released, additional information regarding the product is entered into the online Knowledge Base available on Trellix Service Portal.
Refer to the following tables for a list of Trellix IPS software and hardware documentation:
Trellix IPS software documentation
Guide
Description
Installation Guide
System requirements, installation of the Manager software, management of IPS Sensor/failover pairs, and upgrade steps
Product Guide
A high-level view of how to interact with Trellix IPS
Management of devices, such as IPS Sensors and NTBA Appliances
Obtaining updates from the Trellix IPS Update Server
Monitoring alerts and hosts on your network
In-depth details for inline mode configuration
Management of admin domains, users, and roles
Configuration of MDR
Definition of failover pairs
Various IPS features supported up to the latest Trellix IPS release
Achieving virtualization using IPS Sensor
Creation of custom attacks and signatures using the Custom Attack Editor
Generation of reports
Import of Snort signatures
Troubleshooting techniques for Trellix IPS
Recommended practices for using Trellix IPS most effectively
List of all public and debug CLI commands for IPS Sensors
Initialization, upgrade or replacement of a Sensor, troubleshooting an issue, and performance monitoring for the Sensor
Viewing the system health status of your Trellix IPS components
Configuration and management of Trellix Intrusion Prevention System Central Manager
Management of policies and rule sets
Management of ignore rules
Integration Guide
Integration with:
ePolicy Orchestrator
Global Threat Intelligence
Intelligent Virtual Execution Engine
Network Investigator
Trellix Intelligent Sandbox
Threat Intelligence Exchange
Logon Collector
HP Network Automation
Third-party SIEM products
Manager API Reference Guide
Application Programming Interface (API) framework for external applications to access core IPS functionalities through the REST protocol.
Trellix IPS hardware documentation
Guide
Models
Sensor Hardware Guide
NS9600, NS7600, NS3600
Manager Appliance Hardware Guide
Trellix OS
Manager Appliance Product Guide
MLOS
NS-series Sensor Product Guide
NS9500, NS9x00, NS7500, NS7x50, NS7x00, NS5x00, NS3500, and NS3x00