The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configuring the Process Tracker agent policy

Prev Next

For the Process Tracker to function on the agent, the Real-Time Indicator Detection in Configurations in Edit Policy must be turned on. If you install the module on an agent without turning on real-time indicator detection, no process execution events will be detected.

  1. Log in to the Endpoint Security Web UI as an administrator.

  2. From the Admin menu, select Polices.

  3. Locate the policy you want to edit.

  4. In the Actions column, click the gear icon, and click Edit Policy.

  5. In the Edit Policy page, in Configurations, select Real-Time Indicator Detection.

  6. In the details panel, move the Real-Time Indicator Detection toggle to On.

For information on enabling the Process Tracker, see Enabling the Process Tracker agent module.