Global Updating is a powerful feature, but if used incorrectly it can have a negative impact in your environment.
Global Updating is used to update your repositories as quickly as possible when the Main Repository changes. Global Updating is great if you have a smaller environment (fewer than 1,000 nodes) with no WAN links. Global Updating generates a huge amount of traffic that could impact your network bandwidth. If your environment is on a LAN, and bandwidth is not a concern, then use Global Updating. If you are managing a larger environment and bandwidth is critical, disable Global Updating.
Note
Global Updating is disabled by default when you install ePO - On-prem software.
To confirm the Global Updating setting, select Menu → Configuration → Server Settings and select Global Updating from the Setting Categories list. Confirm that the status is disabled. If not, click Edit and change the status.
If you are a user with a large environment and where bandwidth is critical, you can saturate your WAN links if you have Global Updating enabled. You might think having Global Updating enabled makes you receive their DATs quickly. But eventually, Trellix, for example releases an update to its Trellix Endpoint Security (ENS) engine that can be several megabytes, compared to the 400-KB DAT files. This engine update typically occurs twice a year. When that release occurs the ePO - On-prem server pulls the engine from Trellix, starts replicating it to the distributed repositories, and starts waking up agents to receive the new engine immediately. This engine update can saturate your WAN links and roll out an engine that you might prefer to upgrade in a staged release.
Note
If you have a large environment, you can still use Global Updating, but you must disable it when a new engine or product patch is released or the updates could saturate your WAN links.
For additional information see these KnowledgeBase articles:
How Global Updating works
If your ePO - On-prem server is scheduled to pull the latest DATs from the Trellix website at 2 p.m. Eastern time (and the scheduled pull changes the contents of your Main Repository), your server automatically initiates the Global Update process to replicate the new content to all your distributed repositories.
The Global Updating process follows this sequence of events:
Content or packages are checked in to the Main Repository.
The ePO - On-prem server performs an incremental replication to all distributed repositories.
The ePO - On-prem server issues a wake-up call to all SuperAgents in the environment.
The SuperAgent broadcasts a global update message to all agents in the SuperAgent subnet.
Upon receipt of the broadcast, the agent is supplied with a minimum catalog version needed.
The agent searches the distributed repositories for a site that has this minimum catalog version.
Once a suitable repository is found, the agent runs the update task.