Configuring the indicator update frequency for all host endpoints

Prev Next

To configure the indicator updated frequency for all of your host endpoints:

Important

MIR and Windows xAgent s version 11 apply the indicator update interval setting configured in the agent default policy only. If you add MIR or Windows agents version 11 to a host set that has a real-time indicator detection custom policy that includes changes to the indicator update interval setting, your MIR and Windows agents version 11 will not honor these setting changes. Instead, they will continue to apply the updated interval setting configured in the agent default policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  6. In the Indicator Updates section, enter the indicator updated frequency. Valid values range from 60 to 86400 seconds (one minute to one day). The default is 1800 sections (30 minutes).

    Policy_RTID_IOC_Update_Interval_scap.png
  7. Click Save.