The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Upgrade the signature set for the Central Manager

Prev Next

Release 11.1 and later are compatible with signature set version 11.9.x or 11.10.x depending on the Manager version installed. If you are upgrading from any 10.1.x version, during installation, the signature set bundled with the installer will be imported to the Manager automatically.

Note

For more information on 11.1.x Manager software and compatible signature set versions, refer to Trellix Intrusion Prevention System 11.1.x release notes.

Steps:

  1. If you have not already done so, download the most recent signature set into the Central Manager.

    In the Central Manager, select Manager → <Admin Domain Name> → Trellix IPS Protection Status. Then, select Signature Sets tab. The Signature Sets tab is displayed. Select Download Latest Signature Setoption. See the Trellix Intrusion Prevention System Product Guide or the Online Help for the steps.

  2. If you created Trellix IPS custom attacks prior to upgrade, verify that those attacks are present in the Custom Attack Editor.

  3. Select Manager → Troubleshooting → System Faults to see if Incompatible custom attack fault is raised.

    This fault could be because of Custom Snort Rules that contain unsupported PCRE constructs.

Signature Set upgrade is now complete for the Central Manager. For a list of currently supported protocols, see KnowledgeBase article KB61036 in the Trellix Support Portal.

What is the next step?

  • If you have a Central Manager MDR, refer to section MDR Central Manager upgrade.

  • If you have upgraded both primary and secondary or if you have only a standalone Central Manager, upgrade the corresponding Managers.