You can compare the current whitelist status and checksum values of whitelisted files, directories, and volumes with the status and values stored in the whitelist. If they are not current, you can update the whitelist and fix inconsistencies.
If the components in the whitelist are changed or removed and the whitelist is not updated, the execution of these components is blocked. This results in inconsistencies in the whitelist.
Task
Run this command at the command prompt.
sadmin check [ -r ] file | directory | volume
You can narrow the results by specifying the names of files, directories, and drive/volumes with this command.
Also, you can specify the
-r argument with this command. This argument fixes inconsistencies by updating the whitelist with the latest checksum values of the components and adds the components to the whitelist, if the components are not already present. If you don't specify a component, inconsistencies in all supported drives/volumes are fixed.
Application Control and Change Control > Application and Change Control 6.x > Trellix Application and Change Control 6.5.x - Linux Product Guide > Maintaining your system in an unmanaged environment > Manage the whitelist
Application Control and Change Control > Application and Change Control 6.x > Trellix Application and Change Control 6.6.x - Linux Product Guide > Maintaining your systems > Maintaining your system in an unmanaged environment > Manage the allow list
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Maintaining your systems > Maintaining your system in an unmanaged environment > Manage the allow list