Oversubscription defines how Trellix ESM handles packets if the device's capacity is exceeded. In each case, the packet is recorded as an event. You can set up the default policy to operate in alerts only mode or oversubscription mode. You can also view the status of the rule updates and initiate an update.
On the Policy Editor, click the Settings icon
.In the Oversubscription Mode field, click Update.
In the Value field, enter the functionality.
Pass (pass or 1) - allows packets that would be discarded to pass unscanned.
Drop (drop or 0) - drops packets that exceed the device's capacity.
To pass or drop a packet without generating an event, enter
spassorsdrop.
Click OK.
Note
Changing Oversubscription Mode affects the primary and secondary devices (virtual devices). For this change to take effect, you must change the mode on the primary device.