Last Updated: September 17, 2023
General page (Configuration tab)
Allows you to configure your Trellix ePO - On-prem details, Trellix MOVE AntiVirus SVM (Agentless), and SVM Manager (Multi-Platform) details on the Trellix ePO - On-prem server.
Option | Definition |
|---|---|
ePO Credentials |
|
SVM (Agentless) and SVM Manager (Multi-Platform) Configuration |
|
Save | Click to store these configurations, so that you can use them for every Trellix MOVE AntiVirus SVM (Agentless) or SVM Manager (Multi-Platform) deployment. |
Reset | Click to reset the parameters. |
IP Pool page (Configuration tab)
Before configuring the IP address as Static, create an IP Pool. You can then select this IP Pool during the SVM deployment, so that any unused IP address of the IP Pool is automatically assigned to the SVM.
Option | Definition |
|---|---|
IP Pool Name | Type a name for the IP Pool. |
Start IP | Type the starting IP address for the pool. |
End IP | Type the ending IP address for the pool. |
Gateway | Type the default gateway address. |
Prefix Length | Type the Prefix length. |
Primary DNS | (Optional) Type the IP address of the Primary DNS server for hostname-to-IP address resolution. |
Secondary DNS | (Optional) Type the IP address of the Secondary DNS server for hostname-to-IP address resolution. |
Used / Total | Specifies the total number of IP addresses and the number of used IP addresses of the IP Pool. Example: 2/3 means that 2 IP addresses are used out of the available 3 IP addresses in the IP Pool. |
Actions |
Add IP Pool — Select to configure the IP Pool details required for SVM deployment. |
NSX Manager Registration page
Using this configuration available on the ePolicy Orchestrator - On-prem server, you can edit the details and validate the credentials of your NSX Manager.
Option | Definition |
|---|---|
vCenter Account | Specifies the name of the registered vCenter account. |
NSX Manager Name | Specifies the name of your NSX Manager. Note: Do not include spaces. |
Configuration Status | Displays these registration statuses:
|
Action | Edit — Click to open the Edit NSX Manager Details dialog box and edit the NSX Manager account details. |
Trellix MOVE AntiVirus Service Registration (NSX) page
You can select the required Trellix MOVE AntiVirus SVM version and register it with VMware NSX Manager, which was registered to the Trellix ePO - On-prem server. This allows you to deploy the Trellix MOVE AntiVirus SVM to one or more clusters.
Option | Definition |
|---|---|
NSX Manager Name | Specifies the name of the registered NSX Manager. |
NSX Manager Address | Specifies the IP address of your NSX Manager. |
vCenter Account | Specifies the name of the vCenter account that is registered with NSX Manager and Trellix ePO - On-prem. |
Registered SVM Version | Specifies the version of the Trellix MOVE AntiVirus SVM checked in to Trellix ePO - On-prem. |
Service Registration Status | Displays these registration statuses values:
|
Actions |
|
Edit NSX Manager Details page
Use this page to view and edit the configuration details of your NSX Manager.
Option | Definition |
|---|---|
vCenter Account | Specifies the name of the registered vCenter account. |
NSX Manager Name | Type the name of the available NSX Manager.
|
NSX Manager Address | Type the IP address or the host name of the available NSX Manager. |
NSX Manager Port | Specifies the port number of NSX Manager. |
NSX Manager Username | Type the user name of the available NSX Manager. |
NSX Manager Password | Type the password of the available NSX Manager. |
Validate Credentials | Click to verify the credentials of the NSX Manager and check that the connection to the NSX Manager works. |
Save | Saves the NSX Manager details. |
Cancel | Navigates to the previous page. |
vShield Manager page (Configuration tab)
Use this page to view and edit the configuration details of the vShield Manager.
Option | Definition |
|---|---|
vCenter Account | Specifies the name of the registered vCenter account. |
vShield Manager | Specifies the name of the registered vShield Manager. |
Configuration Status | Displays these configuration statuses:
|
Action | Edit — Click to edit and validate the existing vShield Manager configuration. |
SVM Repository page (Configuration tab)
You must check in and host the SVM package in Trellix ePO - On-prem, so that you can deploy it to the hypervisor. You can view and delete the SVM package using Trellix ePO - On-prem.
Option | Definition |
|---|---|
SVM Name | Specifies the name of the Trellix MOVE AntiVirus SVM package checked in to Trellix ePO - On-prem. |
SVM Version | Specifies the version of the Trellix MOVE AntiVirus SVM package checked in to Trellix ePO - On-prem. |
SVM Use Count | Specifies the number of SVMs, which are present in the infrastructure. |
Action | Delete — To remove an existing Trellix MOVE AntiVirus SVM when it is not deployed to any hypervisor. It is possible to delete the SVM only when the SVM Use Count is zero. Add SVM — Select to open the Check-in SVM (zip) File page. |
Check-in SVM (zip) File page
Allows you to browse and select the SVM package for Agentless deployment, so that it checks-in the SVM package to Trellix ePO - On-prem.
Option | Definition |
|---|---|
SVM OVF Details | Select SVM (zip) file to check-in — Browse to and select the Trellix MOVE AntiVirus SVM package. |
OK | Checks-in the SVM package to Trellix ePO - On-prem. |
Cancel | Cancels the check-in. |
Server Settings page (Configuration tab)
Use this page to view and edit the configuration details of the NSX server.
Option | Definition |
|---|---|
Policy Enforcement Interval (Minutes) | Specifies the interval for policy enforcement in minutes. |
Policy Collector | Enable this option to enforce unique scan policies on specific virtual machines protected by SVM. |
NSX Tagging Interval (Minutes) | Specifies the interval for NSX tagging for detecting malware. |
Run Policy Collector | Click Run to collect the policies that are available in NSX Manager.
|
NSX Tagging | Specifies that the VM is tagged with the tag for detecting malware.
|
Edit | Click to open the Edit Server Settings page and edit the NSX server settings. |
Edit Server Settings page (Configuration tab)
Before deploying the SVM, complete this one-time configuration on the Trellix ePO - On-prem server, so that these settings are retrieved and used for every SVM deployment, which is done from the same Trellix ePO - On-prem server.
Option | Definition |
|---|---|
Policy Enforcement Interval (Minutes) | Specify the interval for policy enforcement in minutes. Default interval time is 60 minutes. |
NSX Tagging Interval (Minutes) | Specify the interval for NSX tagging for detecting malware. Default interval time is 60 minutes. |
NSX Tagging | Allows you to set the tagging settings on detecting malware.
The MCAFEE.MOVE.unprotected=yes tag is automatically removed from the VMs when they are protected. |
Save | Saves the NSX server settings. |
Cancel | Navigates to the previous page. |
Infrastructure Details page (Configuration tab)
After registering your vCenter account, your default virtual group is added to the MOVE AntiVirus Deployment wizard when you access the Infrastructure Details option under Autoscale.
Option | Definition |
|---|---|
Group Name | Specifies the name of the infrastructure group. |
Cloud Account Name | Specifies the account name of the registered vCenter account. |
ESXi / Cluster | Specifies the IP address or name of the hypervisor or the cluster selected as part of the infrastructure group. |
IP Pool Name | Specifies the name of the IP Pool used in the infrastructure group. |
Provisioning Type | Specifies the provision type as Thin or Thick. |
Network Name | Specifies the name of the management network used by the group. |
Datastore Name | Specifies the name of the datastore used by the infrastructure group. |
Action |
|
Actions |
|
Configure Autoscale Infrastructure Group Details page
Allows you to configure these properties for the custom infrastructure group details.
Option | Definition |
|---|---|
Group Name | Type a unique name for the virtual infrastructure group.
|
Infrastructure Type | Select whether you want to create a group based your hypervisor or cluster. |
Select Host or Select Cluster |
|
Hostname Prefix | Type a unique prefix that is added to the host name of the hypervisor or cluster. The prefix can include characters a–z, A–Z, 0–9, and [-], without space. |
IP Pool | Select the IP Pool type as Static or DHCP from the drop-down list. |
AD Server | Select the registered Active Directory server, so that the deployed SVM is automatically added to the selected domain. |
Provisioning Type | Select the provision type as Thin or Thick from the drop-down list. |
Network Name | Select the required management network from the drop-down list. |
Datastore Name | Select the configured datastore for the infrastructure. |
Save | Saves the infrastructure group details. |
Back | Navigates to the previous page. |
Edit Infrastructure Details page (Configuration tab)
This page allows you to edit the properties of an existing infrastructure group details.
Option | Definition |
|---|---|
Group Name | Type a unique name for the virtual infrastructure group.
|
Select Virtual Account | Select the infrastructure cloud account to edit. |
Infrastructure Type | Select whether you want to create a group based your hypervisor or cluster. |
Select Host or Select Cluster |
|
Hostname Prefix | Type a unique prefix that is added to the host name of the hypervisor or cluster. The prefix can include characters a–z, A–Z, 0–9, and [-], without space. |
IP Pool | Select the IP Pool type as Static or DHCP from the drop-down list. |
AD Server | Select the registered Active Directory server, so that the deployed SVM is automatically added to the selected domain. |
Provisioning Type | Select the provision type as Thin or Thick from the drop-down list. |
Network Name | Select the required management network from the drop-down list. |
Datastore Name | Select the configured datastore for the infrastructure. |
Save | Saves the infrastructure group details. |
Back | Navigates to the previous page. |
SVM Manager Configuration (Configuration tab)
Allows you to view and configure the SVM Manager OVF details for SVM Manager deployment to your hypervisor.
Option | Definition |
|---|---|
SVM Manager OVF Name | Specifies the name of the SVM Manager OVF package checked in to the Trellix ePO - On-prem server. |
SVM Manager OVF Version | Specifies version of the SVM Manager OVF package checked in to the Trellix ePO - On-prem server. |
Action |
|
Actions |
|
Deployment Configuration |
|
Check-in SVM Manager OVF (zip) File page
Allows you to check in the SVM Manager OVF package to the Trellix ePO - On‑prem server, so that Trellix ePO - On‑prem can deploy it to your hypervisor.
Option | Definition |
|---|---|
SVM Manager OVF Check-in |
|
OK | Checks in the SVM Manager OVF package to the Trellix ePO - On‑prem server. |
Cancel | Navigates to the previous page. |
Client Deployment Configuration page
Using this page, you can configure and deploy the client package to virtual machines, so that Trellix ePO - On-prem can manage the Trellix MOVE AntiVirus configuration on client systems.
Option | Definition |
|---|---|
Client Configuration | Client Package — Select the client package from the drop-down list for deployment. |
SVM Manager |
|
Proceed | Initiates the client deployment. |
Cancel | Cancels the client deployment. |
SVM Configuration (Configuration tab)
You must configure an SVM OVF template in Trellix ePO - On-prem, so that it is used for SVM autoscaling. You can view and delete the SVM OVF template using Trellix ePO - On-prem.
Option | Definition |
|---|---|
SVM OVF Name | Specifies the name of the Trellix MOVE AntiVirus SVM OVF template checked in to the Trellix ePO - On-prem server. |
SVM OVF Version | Specifies the version of the Trellix MOVE AntiVirus SVM OVF package checked in to Trellix ePO - On-prem. |
SVM OVF Use Count | Specifies the number of SVMs that are deployed for SVM autoscaling. |
Action | Delete — To remove an existing Trellix MOVE AntiVirus SVM when it is not deployed to any hypervisor. It is possible to delete the SVM only when the SVM Use Count is zero. |
Actions | Add SVM — Select to open the Configure SVM OVF page. |
Configure SVM OVF page
Using this page, you can export an SVM OVF template to make a master image of an SVM, from which you can deploy many SVMs. You can also specify the location of the SVM OVF template that you exported using export utility tool, so that Trellix MOVE AntiVirus can deploy SVMs, as needed.
Option | Definition |
|---|---|
Configure SVM OVF template |
|
Proceed | Click to export and check in an SVM OVF template to the Trellix ePO - On-prem server. |
Cancel | Click to cancel the SVM export. |
Autoscale SVM Details page (Configuration tab)
Use this page to view the details of the SVMs, which are deployed using the autoscale feature. You can view the deployed SVM and the infrastructure group details.
Option | Definition |
|---|---|
Preset | Allows you to select an option to filter and display the deployed SVM modes:
|
Hostname | Specifies the host name of the deployed Trellix MOVE AntiVirus SVM. |
Assignment Rule | Specifies the name of assignment rule, which assigns a set of endpoints to a selected SVM or a number of SVMs, so that those clients are protected by the SVM Manager assignment rule. |
Infrastructure Group | Specifies whether it is a hypervisor-based or cluster-based infrastructure group. |
Version | Specifies the version of the SVM. |
SVM Mode | Specifies the mode of the deployed SVM:
|
SVM Status | Specifies whether the SVMs are running. |
Action | Edit — Click to edit the configuration details of a host. |
Actions |
|
Selection page (Service setup)
Allows you to select the hypervisor where the MOVE service and prerequisites have to be installed.
Option | Definition |
|---|---|
Hypervisors | Lists the hypervisors present under the registered VMware vCenter account. |
vCenter Account | Specifies the name of the VMware vCenter account that is registered with Trellix ePO - On-prem. |
Deployment Type | Displays the SVM deployment status as Install or Upgrade. |
Next | Navigates to the next page. |
Cancel | Cancels the current page. |
Configuration page (Service setup)
Allows you to configure SVM Hostname, SVM Version, Datastore, Provision Type, Management Network, and IP Configuration. All these parameters are retrieved automatically and they can be edited later.
Option | Definition |
Hypervisor | Lists the hypervisors present under the registered VMware vCenter account. |
SVM Version | Version of the SVM package checked in to Trellix ePO - On-prem. |
SVM Hostname | Specifies the hostname of the SVM. |
Datastore (Free Space) | Specifies the free space present in the datastore, where the SVM service virtual machines storage is added. |
Provision Type | Specifies the provision type as Thick or Thin. |
Management Network | Displays the management network specified in the SVM. |
IP Configuration | Specifies the DHCP IP or Static IP Pool to be used. |
Action | Click Edit to change the configurations of a single hypervisor. |
Actions | Group Edit — You can select multiple hypervisors and click Actions → Group Edit to change the hypervisor settings, so that the changed values are applicable to all selected hypervisors. |
Back | Navigates to the previous page. |
Next | Saves the hypervisor details and then navigates to the next page. |
Cancel | Cancels the current page. |
Verification page (Service setup)
You can verify the various parameters of the services that are installed during the deployment. This step also validates the prerequisites for the SVM deployment.
Option | Definition |
|---|---|
Hypervisor | Lists the hypervisors present under the registered VMware vCenter account. |
vCenter Account | Specifies the vCenter account of the hypervisor. |
vShield Manager | Specifies the vShield Manager account. |
SVM Version | Version of the SVM package checked in to Trellix ePO - On-prem. |
SVM Hostname | Specifies the hostname of the SVM. |
Datastore (Free Space) | Specifies the free space present in the datastore, where the SVM service virtual machines storage is added. |
Provision Type | Specifies the provision type as Thick or Thin. |
Management Network | Displays the management network specified in the SVM. |
IP Configuration | Displays the IP configuration allotted for the virtual appliance. |
Verification Status | Displays the verification status of these components:
|
Back | Navigates to the previous page. |
Deploy | Deploys the SVM to the selected hypervisor. |
Cancel | Cancels the current page. |
Selection page (Service remove)
Using the Trellix ePO - On-prem console, remove the SVM from one or more hypervisors.
Option | Definition |
|---|---|
Hypervisors | Lists the hypervisors present under the registered VMware vCenter account, where the SVM is already deployed. |
vCenter Account | Specifies the name of the VMware vCenter account that is registered with Trellix ePO - On-prem. |
SVM Version | Specifies the version of the SVM. |
Next | Navigates to the next page. |
Cancel | Navigates to the previous page. |
Verification page (Service remove)
You can review the verification details after selecting the required hypervisors from which you must remove the SVM.
Option | Definition |
|---|---|
Hypervisors | Lists the hypervisors present under the registered VMware vCenter account. |
vCenter Account | Specifies the name of the VMware vCenter account that is registered with Trellix ePO - On-prem. |
SVM Version | Specifies the version of the SVM. |
SVM VM Name | Displays the name of the SVM host. |
Validation Status | Displays the validation status that specifies whether the SVM can be removed. |
Back | Navigates to the previous page. |
Remove | Removes the SVM from the selected hypervisor. |
Cancel | Cancels the current page. |
Job Status page (Service setup)
After initiating the SVM deployment or upgrade, you can view the deployment status and its details on the Trellix ePO - On-prem server.
Item | Description |
|---|---|
Hypervisors | Specifies the name of the hypervisor. |
vCenter Name | Specifies the name of VMware vCenter account that is registered with Trellix ePO - On-prem. |
Deployment Type | Displays whether the SVM deployment type is Deploy, Upgrade, or Remove. |
Status | Specifies the deployment status such as Started, Completed, Failed, Completed with error, and Fatal error. |
Start Time | Indicates the date and time when the SVM deployment started. |
End Time | Indicates the date and time when the SVM deployment ended. |
Deployment and task status details page
After initiating a deployment, you can view the deployment job status and task status details on the Trellix ePO - On-prem server.
Item | Description |
|---|---|
Start Time | Indicates the date and time when the SVM deployment started. |
End Time | Indicates the date and time when the SVM deployment ended. |
Deployment Type | Displays the deployment type: |
Status | Specifies the deployment status such as Started, Completed, Failed, Completed with error, and Fatal error. |
vCenter Name / IP address | Specifies the name of VMware vCenter account that is registered with Trellix ePO - On-prem. |
Hypervisors / Hostname | Agentless: Specifies the name of the hypervisor. Multi-Platform:
|
Task status for Hypervisor
Item | Description |
|---|---|
Node Type | Agentless: Specifies whether the node is an SVM or a hypervisor. Multi-Platform:
|
Task Type | Specifies the set of internal tasks that happen in a deployment or an upgrade job. The task list for a single job is displayed in sequence with Start Time, End Time, and Failure Reasons, if applicable. For the list of tasks and details, see Task status details. |
Node Name | Agentless: Displays the SVM VM name, or Hypervisor name. Multi-Platform:
|
Status | Specifies the task status such as Started, Completed, Skipped, Failed, and In Progress. |
Failure Reason | Specifies the reason for the failure of the task. |
Start Time | Indicates the date and time when the task started. |
End Time | Indicates the date and time when the task ended. |
Task status for Guest
Item | Description |
|---|---|
Node Type | Agentless: Specifies the node as VM. Multi-Platform:
|
Task Type | Specifies the set of internal tasks that happen in a deployment or an upgrade job. The task list for a single job is displayed in sequence with Start Time, End Time, and Failure Reasons, if applicable. For the list of tasks and details, see Task status details. |
Node Name | Displays the VM name. |
Status | Specifies the task status such as Started, Completed, Skipped, Failed, and In Progress. |
Failure Reason | Specifies the reason for the failure of the task. |
Start Time | Indicates the date and time when the task started. |
End Time | Indicates the date and time when the task ended. |
Option | Description |
|---|---|
Back | Navigates to the previous page. |
Close | Closes the current page. |
Options page (Trellix MOVE AntiVirus Common)
Allows you to configure the settings to defend files, services, and registry keys on virtual machines and to log events and alerts.
Option | Definition |
|---|---|
Self-Protection |
|
Events | Allows you to set where to display threat events. Available options are:
|
Logging | Rotate log file content when the file size reaches ____ MB — Enter the maximum size the Rotate Server log files can reach. Default size is 10 MB. |
On-access Scan page (Trellix MOVE AntiVirus)
The Trellix MOVE AntiVirus on-access scan tab contains settings for what files should be scanned and when.
Option | Definition |
|---|---|
On-access scan | Enable on-access scan — Select to use on-access scanning. Scan — Available options (and their default states) are:
More than one option can be selected.
Specify maximum time for each file scan____seconds — The amount of time to wait for a scan to complete, in seconds. Defaults to 45 seconds. This is the duration for which a Trellix MOVE AntiVirus Agent waits for scan response of a file from the SVM. Typically, file scans are fast. However, file scans might take longer time due to large file size, file type, or heavy load on the SVM. In case, the file scan takes longer than the scan timeout limit, the file access is allowed and a scan timeout event is generated. Cache scan results for files smaller than ____MB (Multi-Platform only) — Set the maximum file size (in MB) up to which scan results must be cached. Defaults to 40 MB. Files smaller than this threshold are copied completely to the SVM and scanned. If the file is found to be clean, its scan result is cached based on its SHA‑1 checksum for faster future access. Files larger than this size threshold are transferred in chunks that are requested by the SVM and scanned.
Deferred Scan (Multi-Platform only) — The deferred scan feature optimizes file scanning for files where the previous scanning is timed out for reasons such as large file size, file structure, and file composition. Enable on-access deferred scan — Select to enable the deferred scan. Here are the file size ranges and scan time-out:
|
Actions | Threat detection primary response — If you select Delete files automatically and quarantine or Delete files automatically, and if that fails Deny access to files. If the primary behavior is set to Deny access to files, no secondary action is available. |
Threat Detection | Notify users when a threat is detected on a on-access scan (Multi-Platform only) — Select to notify users when a threat is detected on a on-access scan. |
File types to scan | Specifies what file extensions to scan.
Following only — Select to specify a list of file extensions to scan. You can add, edit, and remove file extensions that are included for scanning. If you click Following only, customize the list of extensions to scan by clicking Add, Edit, or Remove. Do not include the period when specifying extensions. Wildcards are not supported, and exact matches are required. For example, specifying |
Exclusions | Specifies which folders are to be excluded from scanning.
|
MOVE AntiVirus page-level reference
Option | Definition |
|---|---|
the issuing CA — Trellix MOVE AntiVirus checks against the Windows CRL (local cache) that is maintained by Windows locally and also checks against the issuing CA's (certificate authority) CRL that is done over network. Note: CRL = certificate revocation list
|
Enabling Trellix MOVE AntiVirus network scanning capabilities, then accessing files across the network severely impacts the access time for network-based files. Trellix recommends scanning a file using a scanner closest to the file itself. If a file resides on a network share, rather than enabling Trellix MOVE AntiVirus network scanning, use the Trellix anti-virus product on the system where the file resides to scan the file. If the file resides on a NetApp Filer we recommend using VirusScan Enterprise for Storage to scan the file. With this approach you maintain good performance while still providing protection
On-demand Scan page (Trellix MOVE AntiVirus)
The Trellix MOVE AntiVirus on-demand scan page allows you to configure on-demand scan settings for your virtual environment.
Option | Definition |
|---|---|
On-demand scan |
|
Actions | Threat detection first response — If you select Delete files automatically and quarantine or Delete files automatically, and if that fails Notify only. If the first behavior is set to Notify only, no secondary action is available. |
File types to scan | Specifies what file extensions to be scanned.
If you click Following only, customize the list of extensions to scan by clicking Add, Edit, or Remove. Do not include the period when specifying extensions. Wildcards are not supported, and exact matches are required. For example, specifying |
Exclusions | Specifies which folders are to be excluded from scanning.
|
Option | Definition |
|---|---|
File types to scan | Specifies what file extensions to be scanned.
If you click Following only, customize the list of extensions to scan by clicking Add, Edit, or Remove. Do not include the period when specifying extensions. Wildcards are not supported, and exact matches are required. For example, specifying |
Exclusions | Specifies which folders are to be excluded from scanning.
|
Options page (Trellix MOVE AntiVirus)
From the Trellix MOVE AntiVirus Options tab, you can configure the quarantine manager options that apply to both on-access scanner and on-demand scanner. Also, specifies the SVM assignment details for Multi-Platform.
Option | Definition |
|---|---|
Quarantine Manager | (Multi-Platform only)
|
SVM Server Communication | Scan server port — Specifies the port number of the scan server of the SVM. The default port is 9053.
|
SVM Assignment | Assign SVM using SVM Manager — Select to specify which SVM a group of virtual machines uses.
|
39
Shared Cloud Solutions page (MOVE AntiVirus)
Shared Cloud Solutions page allows you to configure settings for using Threat Intelligence Exchange and Intelligent Sandbox features.
Option | Definition |
|---|---|
Enable TIE | Enabled — Select to enable Threat Intelligence Exchange so that it provides context-aware adaptive security for your virtual environment. TIE determines file and certificate reputation when a Portable Executable (PE) file is accessed on a managed endpoint. PE file includes these formats: .cpl, .exe, .dll, .ocx, .sys, .scr, .drv, .efi, .fon |
TIE Non-PE Lookup | Enabled — Select to enable Threat Intelligence Exchange to determine file and certificate reputation when a non-PE file is accessed on a managed endpoint. |
Threat Intelligence Exchange (TIE) | Select the reputation action from the drop-down list to scan by Threat Intelligence Exchange. Available options are:
|
Advanced Threat Defense (ATD) | Allows you to define the settings for use of Intelligent Sandbox feature.
|
SVM Manager Settings page (MOVE AntiVirus)
Configure these SVM Manager settings that allow you to set the OSS assignment and threshold warning.
Option | Definition |
|---|---|
SVM Manager Configuration | SVM Manager configuration allows you to assign your SVM to your client systems based on the configurations specified in the Trellix ePO - On-prem server.
|
SVM Autoscale Settings | Enable auto scaling of SVMs — Enabling this option deletes all existing SVMs after the new SVMs are deployed and are ready to protect the client systems. It is also important to note that disabling the Enable auto scaling of SVMs option deletes all ready and standby SVMs, but the running SVMs continue to protect the client systems.
|
Assignment Rules | Tag Assignment Rules — Displays the list of assigned rules that have been created using their tag group for a set of endpoints to a selected SVM.
IP Assignment Rules — Displays the list of assigned rules that have been created using their IP address range for a set of endpoints to a selected SVM.
|
SVM Settings page (MOVE AntiVirus)
SVM Settings page allows you to configure SVM, enable Trellix GTI, and on-demand scan (ODS) scheduler.
Option | Definition |
|---|---|
SVM Settings | Concurrent on-demand scans — Allows you to define on-demand scan settings per SVM.
(Multi-Platform only)
|
Trellix GTI | Enable Trellix GTI — Select to enable Trellix GTI scan feature.
|
Scanning Options |
|
ODS Scheduler | Allows you to set on-demand scanning time on day-to-day and time-to-time basis. |
Performance |
(Agentless only)
|
SVM Configuration | (Multi-Platform only)
(Agentless only)
This is important for the on-demand scan to start at the exact time you have specified.
|
Schedule page (Targeted on-demand scan)
Use this page to specify the schedule for targeted on-demand scan.
Option | Definition |
|---|---|
Schedule status | Specifies whether the task runs according to its schedule. If the schedule is disabled, the task can only be run from the Systems → System Tree page by clicking Actions → Targeted ODS [MOVE]. |
Schedule type | Specifies the interval for running the targeted on‑demand scan task. Options include:
|
Effective period | Specify the following:
|
Start time | Specify the time at which this task need to begin, and:
|
Task runs according to | Specifies whether the task schedule runs according to the Local time on managed system or Coordinated Universal Time (UTC). |
Options | Specifies how the task behaves and the actions that can be taken if the task runs too long, or whether the task should run if it was missed. Options include:
|
Next | Navigates to the Summary page. |
Save | Saves and runs the targeted on-demand scan for the selected VMs. |
Cancel | Navigates to the current page. |
Summary page (Targeted on-demand scan)
Review the details of the task assignment before saving it.
Option | Definition |
|---|---|
Name | Displays the name you provided for the task assignment. |
Description | Displays any description you provided for the task assignment. |
Type | Displays the type of task chosen for this assignment. |
Schedule | Displays the schedule information provided for this task assignment. |
Lock task inheritance | Displays whether task inheritance was locked for this task assignment. |
Back | Navigates to the previous page. |
Save | Saves the assignment. |
Cancel | Navigates to the current page. |