Configuring the indicator update frequency

Prev Next

At a specified interval, the xAgent establishes a secure connection with the appliance and downloads the latest indicators. Indicator update packages are signed and encrypted files containing versioned sets of indicators and conditions. This setting is also called the indicator refresh interval.

Valid values for the indicator update frequency range from 60 to 86400 seconds. The indicator update frequency distributed with the Trellix Endpoint xAgent software is 1800 seconds (30 minutes).

You can set the indicator update frequency using the Web UI or the API. This section covers how to configure the indicator update frequency for real-time indicator detection indicator using the Web UI. See the Endpoint Security (HX) REST API Guide for more information on configuring your real-time indicator settings.

Prerequisites
  • Admin access to the Web UI

Configuring the indicator update frequency for all host endpoints

To configure the indicator updated frequency for all of your host endpoints:

Important

MIR and Windows xAgent s version 11 apply the indicator update interval setting configured in the agent default policy only. If you add MIR or Windows agents version 11 to a host set that has a real-time indicator detection custom policy that includes changes to the indicator update interval setting, your MIR and Windows agents version 11 will not honor these setting changes. Instead, they will continue to apply the updated interval setting configured in the agent default policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  6. In the Indicator Updates section, enter the indicator updated frequency. Valid values range from 60 to 86400 seconds (one minute to one day). The default is 1800 sections (30 minutes).

    Policy_RTID_IOC_Update_Interval_scap.png
  7. Click Save.

Configuring the Indicator Update Frequency for Selected Host Sets

To configure the indicator updated frequency for selected host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

If you disable a custom policy, the policy settings are disabled for all host sets assigned to the policy. If you want select host sets to keep the custom policy settings, you must create a new custom policy with the setting enabled and assign it to the selected host sets.

important.png

MIR and Windows agents version 11 apply the indicator update interval setting configured in the agent default policy only. If you add MIR or Windows agents version 11 to a host set that has a real-time indicator detection custom policy that includes changes to the indicator update interval setting, your MIR and Windows agents version 11 will not honor these setting changes. Instead, they will continue to apply the updated interval setting configured in the agent default policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  5. In the Events section, toggle the Capture UDP Events ON/OFF switch to ON.

    Policy_RTID_IOC_Update_Interval_scap.png

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.