The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Troubleshooting Tips

Prev Next

This section describes the issues that you might face when working with the Snort rules and the corresponding troubleshooting tips.

Issue: Suricata Snort rules are imported successfully in the Manager but the Sensor does not generate alerts.

Cause: The Snort rules might be failing in the Sensor.

The Sensor does not generate alerts for the failed rules. The Sensor sends the information about the failed rules to the Manager. Information about the failed rules in the Sensor is available in a log file. To view the log file, go to the Manager → <Admin domain> → Troubleshooting → Logs page in the Manager.

You can also verify the number of rules processed by a Sensor by using the show suricata sbstats command. For more information, see the CLI commands to monitor Snort section.

Issue: An alert does not contain the packet information.

Cause: It is possible that the alert might be generated for a buffered packet attack.

The Suricata engine integrated into the Sensor performs packet buffering. When a buffered packet attack is detected and an alert is generated, the Sensor may not have the actual packet information if the alert was raised based on the buffered packet data. In such a scenario, the alert will not have any packet information.