You can track content and attribute changes by configuring these settings.
On the ePO - On-prem console, select Menu → Policy → Policy Catalog.
Select the Solidcore 8.x.x: General product.
The Trellix Default policy includes customizable configuration settings.
In the Configuration (Client) category, click Duplicate for the Trellix Default policy.
Specify the policy name, then click OK.
The policy is created and listed on the Policy Catalog page.
Click the new policy.
Switch to the Miscellaneous tab and specify values for the settings.
Setting
Description
Maximum file size
By default, you can track changes for any file with a size of 1000 KB or lower. You can also configure the maximum file size for tracking content changes.
Note
Changing the maximum file size affects the ePO - On-prem database sizing requirements and might have an impact on performance.
File-extensions for attributes-only tracking
For executable files, the content change tracking feature tracks only attributes (content changes aren't tracked). By default, only attribute changes are tracked for these extensions.
zip
bmp
7z
pdf
rar
tar
gz
bz
tgz
bz2
jpg
exe
gif
dll
tiff
sys
png
jar
You can edit the list to specify file extensions specific to your setup for which to track only attribute changes.
Maximum file limit per rule
When you apply the content change tracking rule on a directory, base versions of all files in the directory that match the specified include or exclude patterns, if any, are collected and sent to the ePO - On-prem server. These base versions are used to track content changes and allow comparison with future versions of the files.
If the number of qualifying files for one rule is too high, operational performance of the endpoint and occasionally of the ePO - On-prem server can deteriorate. To prevent such disruptions, you can specify a value to control the maximum files to retrieve per rule. This limit applies to the number of qualifying files in the directory and not to the total number of files in the directory. If the number of qualifying files for a specified rule exceeds the set threshold value, the base versions of the files aren't retrieved to the server. All subsequent changes to the files are reported and base versions of new files are sent to the server.
By default, the limit is set to 100 files per rule. You can configure this setting, as needed.
Save the policy and apply it to the relevant endpoints.