You can use the Web UI to manage real-time indicator detection.
You can modify the xAgent to enable and disable real-time indicator detection for all agents in your enterprise. By default, real-time indicator detection is enabled. See Disabling Real-Time Indicator Detection and Enabling Real-Time Indicator Detection.
You can also define a custom policy that disables real-time indicator detection for selected host sets. See Excluding Host Sets from Real-Time Indicator Detection.
If you are running Trellix Endpoint Security (HX) xAgent version 27 or later on Windows or macOS, or version 30.19 on Linux, you can create a custom policy that excludes specified files and folders from real-time indicator detection. See Excluding Files and Folders from Real-Time Indicator Detection.
Important
Endpoint Security (HX) xAgent's real-time indicator detection file and folder exclusions policy is supported on Windows and macOS endpoints only.
This section covers how to use the Web UI to configure your real-time indicator detection for all of your host endpoints or for select host sets in your environment. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your Real-Time Indicator Detection policies.
PrerequisitesAdmin access when using the Web UI
Endpoint Security (HX) xAgent version 20 or later installed on your Windows or macOS endpoint, or Endpoint Security (HX) xAgent version 30.19 or later installed on your Linux endpoint. If an xAgent for an earlier release is included in a host set that is managed by a policy, the policy is ignored for that xAgent .