The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Tune your policies

Prev Next

The default Trellix IPS policy templates are provided as a generic starting point; you will want to customize one of these policies for your needs. So the first step in tuning is to clone the most appropriate policy for your network and your goals, and then customize it. (You can also modify a policy directly rather than modifying a copy.)

Some things to remember when tuning your policies:

  • We ask that you set your expectations appropriately regarding the elimination of false positives and noise. A proper Trellix IPS implementation includes multiple tuning phases. False positives and excess noise are routine for the first 3 to 4 weeks. Once properly tuned, however, they can be reduced to a rare occurrence.

  • When initially deployed, Trellix IPS frequently exposes unexpected conditions in the existing network and application configuration. What may at first seem like a false positive might actually be the manifestation of a mis-configured router or Web application, for example.

  • Before you begin, be aware of the network topology and the hosts in your network, so that you can enable the policy to detect the correct set of attacks for your environment.

  • Take steps to reduce false positives and noise from the start. If you allow a large number of "noisy" alerts to continue to sound on a very busy network, parsing and pruning the database can quickly become a cumbersome task. It is preferable to all parties involved to put energy into preventing false positives than working around them. Exception objects are also an option where you can have custom rule sets specific to your environment. You can disable all alerts that are obviously not applicable to the hosts that you protect. For example, if you use only Apache web servers, you can disable IIS-related attacks.