Configuring the Malware Protection indicator download channel

Prev Next

Malware protection indicators are used by the Endpoint Security (HX) xAgent malware protection engine during malware detection scans. Malware definitions, which include malware protection indicators, are transferred through the channel you select.

The Malware Definition Source drop-down allows you to select which channel you want to use to download the latest malware definitions, which include malware protection indicators, to the agents on your host endpoints.

Note

Trellix Endpoint Security (HX) xAgent version 26 supports the Malware Definition Source setting on Windows endpoints only. Windows endpoints running earlier versions of Trellix Endpoint Security (HX) xAgent software will silently ignore this setting.

The table below lists the available channels. The Internet is the default channel.

Indicator Source

Description

Internet (default)

Malware protection indicator updates are downloaded directly from the Internet. Trellix recommends using this setting in cloud environments to prevent performance issues on the Endpoint Security (HX) Server.

HX Preferred

Malware protection indicator updates are downloaded from the Endpoint Security (HX) server. If the Endpoint Security (HX) server is unavailable, malware protection indicator updates are downloaded from the Internet.

HX Only

Malware protection indicator updates are downloaded from the Endpoint Security (HX) server only.

Custom Source

Malware protection indicator updates are downloaded from a configured content server (a custom source). If the custom source is unavailable, malware protection indicator updates are downloaded from the Endpoint Security (HX) server instead. If the Endpoint Security (HX) server is unavailable, then the malware protection indicator updates are downloaded via the Internet. For instructions on configuring a custom source, see Custom Source Location.

Important

Custom Source is available only to xAgent versions 33 and higher.

Note

When you first enable malware protection, the latest malware definitions are downloaded to your agents. By default, this initial download can take up to four hours to complete. Malware protection will not start until these definitions have been downloaded. To verify that the data has downloaded successfully, review the Host Details tab in the Endpoint Security (HX) Web UI for a Windows host. Verify the values in the Content Version and Last Updated fields under Malware Protection on the tab. For more information, see the Endpoint Security (HX) Server User Guide.

This section describes how to configure the download channel for malware protection indicators for all of your host endpoints and for selected host sets in your environment using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to define the download channel for malware protection indicators.