Submitting more than approximately 2,000 files per hour of image files (.gif, .jpeg, and .png) and plain-text files for analysis can delay the analysis of malicious binaries. If the number of files submitted increases the submission or message queue to the configured Analysis Bypass threshold, further traffic is not analyzed. For details about how to configure the Analysis Bypass option, see the Configuring congestion control using the Web UI or Configuring congestion control using the CLI.
If you do not want to impact appliance performance, you can choose not to enable the submission of image and text files for analysis.
Important
Before you enable the submission of image and text files on the Trellix 300 models, contact Trellix Customer Support.
Note
Text attachments that contain a "Content-Type: message/delivery-status" line within an email message body are not submitted for analysis.
Image and text files are not submitted for analysis by default. You enable each option separately. When you enable the submission of image and text files on the Email Security - Server appliance, the Search Emails > Processed Mail page lists the email with the image and text files and whether the analysis of the file type is enabled or disabled by file association. When you disable the submission of image and text files on the Email Security - Server appliance, the Search Emails > Processed Mail page lists the email without the image and text files.