You can improve the performance of Trellix EDR running on Windows servers. These configuration methods can improve performance, but Trellix EDR can lose visibility into all devices. As a result, all threats may not be detected.
Trellix EDR network flow
From Menu → Policy → Policy Control, select the Network Flow tab and deselect Collect TCP/UDP System process information (Windows only).
Prevent Trellix EDR from tracking and keeping a history of all connections to save disk and CPU usage. To do this, ignore the network traffic from the binary that attends to network requests. Configure this behavior through the Trellix EDR device policy in ePO - On-prem or ePO - SaaS by using the full path of the binary. For example:
Apache server — C:\Apache24\bin\httpd.exe
IIS web server — C:\Windows\System32\inetsrv\w3wp.exe
Trellix EDR file hashing
Select the File Hashing tab and set the Hash Strategy to Low.
Ignore folders where: The server logs and data is saved, the server databases are located, and the servers data backup folders are located. This prevents Trellix EDR from tracking and keeping a history of all files created, deleted, and changed, avoiding demands on disk and CPU usage. For example:
Apache server — C:\Apache24\logs; C:\Apache24\htdocs
IIS web server — C:\inetpub\wwwroot; C:\inetpub\logs
Trellix EDR file hashing for SQL Server
Select the File Hashing tab and disable the plug-in. If the file hashing is disabled, the File Hash collector from real-time search does not return results for that endpoint. However, the file activity is monitored as part of the trace and there will be limited visibility for those files created/deleted during the retention timeframe.
Ignore these SQL Server policy extensions:
ldf,mdf,adf,bak.Ignore FOLDERID_ProgramFiles\Microsoft SQL Server and the backup folder.
Trellix EDR traces
When tracing is excluded for a process, file, or folder, there will be no visibility of those files created, deleted, or modified.