For most enterprises, the default settings for the throttling feature are enough. But, if needed, you can change the default configuration for the feature.
On the ePO - On-prem console, select Menu → Policy → Policy Catalog.
Select Solidcore 8.x.x: General for the product.
In the Configuration (Client) category, click Duplicate for the Trellix Default policy.
Specify the policy name, then click OK.
Open the policy and click the Throttling tab.
Edit the values for events, as needed.
Value
Description
Events
The value for threshold and cache size is defined in number of event XML files. By default, 2000 XML files can be processed per endpoint in 24 hours. Also, the default event cache size is set to 7000 XML files per endpoint.
Save the policy and apply it to the relevant endpoints.
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Maintaining your systems > Maintaining your system in a managed environment > Administering throttling for your enterprise
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.3.x - Windows Product Guide > PG - MCC-MAC - Maintaining your systems > Maintaining your system in a managed environment > Administering throttling for your enterprise
Application Control and Change Control > Application and Change Control 9.x > Trellix Application and Change Control 9.0.x - Windows Product Guide > Maintaining your systems > Maintaining your system in a managed environment > Administering throttling for your enterprise