You can use the following information to verify if you have deployed the Virtual Sensor correctly and if it is inspecting traffic.
Steps:
Make sure the Sensor management port and the Manager server can reach each other.
On the Sensor CLI, use the
statusandshowcommands to see whether the trust is established, the channels are up, and the Sensor is in good health.On the Manager Dashboard, check the System Faults monitor to verify if the Sensor is active.
In the Manager, select Devices → <Admin Domain Name> → Devices → <Device name> → Setup → Physical Ports and check if the monitoring ports are up.
Verify if the client and server are reachable to one another.
Send a sample attack from the client to the server, for example, execute root.exe, and check if an alert is raised in the Attack Log with the correct details.
After you deploy a Virtual Sensor, the process of configuring and managing it is similar to that of a physical Sensor. Therefore, refer to the relevant sections in the Trellix Virtual Intrusion Prevention System Product Guide for more details.