Configure automatic triage throttling settings

Prev Next

Caution

Do not change the triage throttling settings without consulting Trellix Customer Support.

You can use the Automatic Triage Settings page to control whether the Endpoint Security (HX) appliance generates automatic triage collections when a widespread compromise or false positive is generating inordinate numbers of triage requests. Throttling settings allow you to specify the number of automatic triage requests that can be generated (request limit) and the time period (in seconds) during which they can be generated.

The following table lists the settings that you can configure on the Automatic Triage Settings page.

Global Triage Settings

Maximum Triages

Controls the maximum number of automatic triage collection requests created globally during a set time period. Valid time periods range from 0-604800 seconds. Valid request limits range from 0-65535 requests.

Configuration properties

Default

Limit

5000 (requests)

automatic triage(s) every

21600 (seconds)

Per Individual Agent

Controls the number of automatic triage collection requests created for unique agents during a set time period. Valid time periods range from 0-604800 seconds per agent. Valid request limits range from 0-65535 requests per agent.

Configuration properties

Default

Limit

1 (requests per agent)

automatic triage(s) every

1800 (seconds)

Per Agent and Condition

Controls the number of automatic triage collection requests created for unique conditions occurring for an individual agent during a set time period. Valid time periods range from 0-604800 seconds per condition per agent. Valid request limits range from 0-65535 requests per condition.

Configuration properties

Default

Limit

1 (request per specific alerting condition)

automatic triage(s) every

43200 (seconds)

Alert Type Specific Settings

Real-Time Detection (IOC)

Controls the number of automatic triage collection requests created for all indicator of compromise (IOC) rules during a set time period. Valid time periods range from 0-604800 seconds. Valid request limits range from 0-65535 requests.

Configuration properties

Default

Limit

75

automatic triage(s) every

21600

Per Condition: Limit of

20

automatic triage(s) every

43200

Per Indicator: Limit of

20

automatic triage(s) every

43200

Exploit Guard Detection (EXD)

Controls the number of automatic triage collection requests created for exploit incidents identified by Exploit Guard during a set time period. Valid time periods range from 0-604800 seconds. Valid request limits range from 0-65535 requests.

Configuration properties

Default

Limit

75 (requests per specific exploit condition)

automatic triage(s) every

21600 (seconds)

Process Tracker* (PRO)

Controls the number of automatic triage collection requests created for alerts identified by Process Tracker during a set time period. Valid time periods range from 0-604800 seconds. Valid request limits range from 0-65535 requests

Configuration properties

Default

Limit

75 (requests per PRO)

automatic triage(s) every

21600 (seconds)

* This alert type is only available if you are using the Process Tracker module in conjunction with the Enricher module, and you have configured these modules to generate PRO alerts.

Prerequisites
  • Admin access