Determine which events are forwarded immediately

Prev Next

Determine whether events are forwarded immediately or only during agent-server communication.

If the currently applied policy is not set for immediate uploading of events, either edit the currently applied policy or create a Trellix Agent policy. This setting is configured on the Threat Event Log page.

  1. Select MenuPolicyPolicy Catalog, then select Trellix Agent on the Products pane and expand the General category.

  2. Click an existing agent policy.

  3. On the Events tab, select Enable priority event forwarding.

  4. Select the event severity.

    Events of the selected severity (and greater) are forwarded immediately to the server.

  5. To regulate traffic, type an Interval between uploads (in minutes).

  6. To regulate traffic size, type the Maximum number of events per upload.

  7. Click Save.