Configuring the update interval for malware protection indicators

Prev Next

Using the Endpoint Security (HX) Web UI or the API, you can specify the interval, in seconds, at which the latest malware definitions that include malware protection indicators should be retrieved and downloaded to the agents on all of your host endpoints or select host sets in your environment.

Note

Malware definition rule updates are available for Windows agents version 24 or later only.

When Endpoint Security Agent (HX) starts an update, it picks a random interval for the content download between 0 and the configured polling interval, which by default is 14400 seconds (4 hours). If the download does not succeed or the content is corrupt, Endpoint Security Agent (HX) attempts the download again using another random interval. Once the download succeeds, the update process stops until the next update interval.

Important

When you first enable malware protection, the latest malware definitions are downloaded to your agents. By default, this initial download can take up to four hours to complete. Malware protection will not start until these definitions have been downloaded. To verify that the data has downloaded successfully, review the Host Details tab in the Endpoint Security (HX) Web UI for a Windows host. Verify the values in the Content Version and Last Updated fields under Malware Protection on the tab. For more information, see the Endpoint Security (HX) Server User Guide.

This section describes how to configure the update interval for all of your host endpoints and for selected host sets in your environment using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to define the update interval for malware protection indicators.