The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use Bulk Edit for IPS policy

Prev Next

On the Policy tab, select the Domain. Then go to Intrusion Prevention → Policy Types → IPS.

The bulk edit feature enables you to select and edit multiple attack definitions at once. This operation is useful for configuring the same responses for multiple attacks at once, thus reducing overall configuration time.

  1. In the IPS page, select the required policies from the list.

    Note

    You cannot bulk edit attack definitions with different attributes. For example, Exploit and Policy Violation attack categories can be edited at the same time, but the DoS Learning Attack can be edited only with other DoS Learning Attacks.

    The following attack categories combination can be edited at the same time:

    • Exploit, Policy Violation, Malware, and Reconnaissance Signature Attack

    • DoS Learning Attack

    • DoS Threshold Attack

    • Reconnaissance Correlation Attack

    Press the Shift key (for continuous selection) or press the Ctrl key (for discontinuous selection), then select the policies.

  2. Click GUID-6E2D5582-3868-4FBA-BA20-20A3995E8669-low.png.

    The Bulk Policies Edit confirmation window appears, prompting to confirm whether you wish to edit multiple policies at the same time.

    Bulk Policies Edit
    Bulk Policies Edit


  3. Click Yes to confirm.

    The Attack Definitions tab is displayed with the list of attacks.

  4. On the Attack Definitions tab, double-click on the row of the attack that you want to configure and update the settings. The attack details are displayed on the right panel displaying the settings under the Settings tab.

    Settings tab
    Settings tab


  5. Configure the settings for the attack definitions.

  6. Click Save to save changes.

    Note

    The Settings tab in the bulk edit has the same configuration fields as displayed for the policy which is selected individually. But when you save the settings, the changes to the attack definitions are applied to all policies that are selected in bulk.