Capturing Network Events

Prev Next

Linux servers generate a large number of network events. Disabling the Capture UDP Events toggle does not always sufficiently reduce the performance impact on the server due to network event generation. The Capture Network Connection Events toggle disables the capture of all network events and decreases the performance impact on your server. Disabling network event capture reduces the detection of IOCs. It is not recommended unless it is to mitigate a performance issue.

For more about this issue, see the Trellix Community Article.

This section covers how to use the Web UI to enable or disable network event capturing for real-time indicator detection.

Important

On hosts with a high number of events, some events may not be recorded.

Enabling or Disabling Network Event Capture

To enable or disable the capture of network events:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

  5. In the Events section, toggle the Capture Network Connection Events switch to ON to enable network event capture. Toggle the Capture Network Connection Events switch to OFF to disable network event capture.

  6. Click Save.