Using the Endpoint Security (HX) Web UI or the API, you can specify the interval, in seconds, at which the latest malware definitions that include malware protection indicators should be retrieved and downloaded to the agents on all of your host endpoints or select host sets in your environment.
Note
Malware definition rule updates are available for Windows agents version 24 or later only.
When Endpoint Security (HX) starts an update, it picks a random interval for the content download between 0 and the configured polling interval, which by default is 14400 seconds (4 hours). If the download does not succeed or the content is corrupt, Endpoint Security (HX) attempts the download again using another random interval. Once the download succeeds, the update process stops until the next update interval.
Important
When you first enable malware protection, the latest malware definitions are downloaded to your agents. By default, this initial download can take up to four hours to complete. Malware protection will not start until these definitions have been downloaded. To verify that the data has downloaded successfully, review the Host Details tab in the Endpoint Security (HX) Web UI for a Windows host. Verify the values in the Content Version and Last Updated fields under Malware Protection on the tab. For more information, see the Endpoint Security (HX) Server User Guide.
This section describes how to configure the update interval for all of your host endpoints and for selected host sets in your environment using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to define the update interval for malware protection indicators.
Configuring the Update Interval for All Host Endpoints
To set the update interval for the malware protection indicators for all host endpoints:
Note
After you save, click Reset to defaults to revert the Malware Definition Source and the Update Malware Definition Rules settings to the default settings.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link to access the Edit Policy page.
Select the Malware Protection tab.
In the Malware Definition Updates section, enter the malware protection indicators update frequency in the Update Malware Definition Rules fields. Valid values range from 1800 to 86400 seconds (30 minutes to one day). The default is 14400 seconds (four hours).
.png)
Click Save.
Configuring the Update Interval for Selected Host Sets
To set the update interval for the malware protection indicators for selected host sets:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Malware Definition Updates section, enter the malware protection indicators update frequency in the Update Malware Definition Rules fields. Valid values range from 1800 to 86400 seconds (30 minutes to one day). The default is 14400 seconds (four hours).
.png)
Click Save.
Note
After you save, click Reset to defaults to revert the Malware Definition Source and the Update Malware Definition Rules settings to the default settings.
Now you can assign host sets to the custom policy and set the policy priority level. See for more information.