Automatically writes the data source setting to the Trellix Enterprise Security Manager - Event Receiver on upgrade.
This feature writes out to the device when the following conditions are met:
Device upgraded before write out (for high availability, both the devices must be upgraded).
Device is not disabled.
Note
If the device is disabled before upgrade, the auto write also be disabled and user has to manually write out.
Device is keyed.
It checks the conditions for each device in every 5 minutes. The system continuously tries to write out data sources until it succeeds. To view the AutoWriteout logs, enable policyDebug using ToggleDebug -f "policyDebug=1". The logs are found in /var/log/messages.
During auto writeout data sources, the following devices are auto write:
Trellix Enterprise Security Manager - Event Receiver
Trellix Application Data Monitor
RECELM (Trellix Enterprise Security Manager - Event Receiver and Trellix Enterprise Security Manager - Enterprise Log Manager)
Trellix ESM - ACE
When the user clicks the Write option in the Data Sources page and a write is already in progress, an error 90 (Job already exists) is displayed. For more information, see KB94427.