The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Verify successful installation

Prev Next
  1. Type status in the Sensor CLI.

    The status report appears.

    VerifySuricataSensor.png

    The Sensor parameter System Initialized should be yes, and for Manager communication Trust Established should be yes.

    Important

    When the Sensor starts, the status is uninitialized. You must manually import and deploy the ruleset to the NS9600 Suricata Sensor. Run the downloadstatus command to check the status.

  2. From the Manager Dashboard, view the Manager status in the System Faults monitor.

    The Manager status displays as Up and Sensor status is Active.

    1-VerifySuccessinstall.jpg
  3. From the Manager, click Devices → <Admin Domain> → Devices → Setup → Physical Ports to view the port details of the standalone Sensor.

    Physicalports_standalone.jpg

    Click Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-Node ID> → Setup → Physical Ports to view the port details of a Sensor in a stack.

    Physicalports_stack.jpg

    Important

    If you have configured 100/40 Gigabit SR MTP/MPO or BiDi with internal fail-open network interface modules with the 100 Gbps speed and you want to reconfigure the speed to 40 Gbps, you may have to click Disable and then Enable the ports once or twice and refresh the Monitoring Ports tab to bring up the ports. This also applies to 100/40 Gigabit SR MTP/MPO interface module.

  4. A policy named Default Prevention is active upon the addition of the Sensor. To view this policy, select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.

    The Default Prevention policy contains attacks already configured with a "blocking" Sensor response action. If any attack in the policy is triggered, the Sensor automatically blocks the attack. To tune this or any other Trellix-provided policies, you can clone the policy and then customize it as described in Trellix Intrusion Prevention System Product Guide.