Configure the EDRF policy to send trace data

Prev Next

To enable the EDRF Client to send trace data to the EDR Telemetry Store, you must configure the General and Streaming policies. Additionally, configure Detection, Investigation, and Remediation policies to enable threat detection, investigation, and response capabilities.

Note

Protection capabilities are provided through Trellix Endpoint Security (ENS). Deploy ENS on the endpoints and configure the required protection policies in ENS to enable protection features. For more information about configuring ENS policies, see the ENS documentation.

Configure the General policy

For more information about General policy settings, see General policy.

  1. Log on to ePO - On-prem On-prem as an administrator.

  2. Navigate to MenuPolicyPolicy Catalog.

  3. From the Product list, select Trellix EDR with Forensics.

  4. Expand the General category, then click Edit for the policy you want to configure.

  5. Click Show Advanced to view all policy settings.

  6. Verify that the following policy settings are enabled by default:

    • Trellix EDR with Cloud

    • Trellix EDR with Forensics Logging

    • Proxy Settings for EDR with Forensics

    Disable the EDR Content Updates setting.

    Note

    Do not use the default setting in EDRF On-prem environment. The default setting allows endpoints to bypass the local server and fetch updates directly from the internet. Administrators must apply updates manually using the Client Task Catalog. For details, see Distribute EDRF content updates locally.

  7. Click Save.

Distribute EDRF content updates locally

EDRF content packages improve detection capabilities and endpoint performance. These packages adjust data collection and streaming processes. They reduce the generated telemetry volume and improve visibility into endpoint actions.

  1. Download new EDRF content packages from the Trellix download portal or Software Catalog.

  2. In ePO, go to MenuMain Repository and select Check In Package.

  3. Click Choose File and select the downloaded content package.

  4. Verify these settings:

    • Package info — Verify the package details.

    • Branch — Select the repository branch. Use the Evaluation branch to test new packages.

      Note

      Move tested packages to the Current branch in the Main Repository.

    • Options — Select one of these actions:

      • Move the existing package to the Previous branch — This setting archives the current package when you check in a newer version. This option is only available for the Current branch.

      • Package signing — This field identifies if the package is from Trellix or a third party.

  5. To update the content package, follow the steps mention in Deploy EDRF using ePO - On-prem using Client Task.

Configure the Streaming policy

  1. On the Policy Catalog page, expand the Streaming category.

  2. Click Edit for the policy you want to configure.

  3. Verify that the following policy settings are enabled by default:

    • Enable Trace

    • Enable deep inspection of Windows API calls

    • Enable ETW-TI of Windows API calls

    • Send traces to Trellix EDR Cloud

    • Alerts Streamed to EDR Cloud

    Note

    Do not disable the Send traces to Trellix EDR Cloud or Alerts Streamed to EDR Cloud settings. The endpoint client uses these services to send trace data to the Data Exchange Layer (DXL). The DXL then routes telemetry to your local on-premises telemetry store. If you disable these settings, you disrupt the trace data flow.

  4. You can Configure the storage and interval settings for the trace data as needed.

  5. Click Save.

For more information about Streaming policy settings, see Streaming policy.

Configure the Detection policy

  1. On the Policy Catalog page, expand the Detection category.

  2. Click Edit for the policy you want to configure.

  3. Verify that the following policy settings are enabled:

    • Enable Real-Time Indicator Detection

    • Capture Network Connection Events

    • Capture DNS Events

    • Capture URL Events

  4. You can add process and trace rule exclusions to limit the amount of telemetry data generated by the system.

  5. Click Save.

For more information about Detection policy settings, see Detection policy.

Configure the Investigation policy

  1. On the Policy Catalog page, expand the Investigation category.

  2. Click Edit for the policy you want to configure.

  3. Verify that the following policy settings are enabled by default:

    • Enable process history

    • Enable Network flow collector

  4. You can exclude processes from network collection by entering their full file path on Windows endpoints. This prevents the system from collecting TCP and UDP information for these specific processes.

  5. Click Save.

For more information about Investigation policy settings, see Investigation policy.

Configure the Remediation policy

  1. On the Policy Catalog page, expand the Remediation category.

  2. Click Edit for the policy you want to configure.

  3. Verify that the following policy settings are enabled by default:

    • Enable the option to display the message on containment actions

  4. You can exclude application paths from containment for Windows, macOS or Linux endpoints.

For more information about Remediation policy settings, see Remediation policy.