The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Define packet oversubscription

Prev Next

Oversubscription defines how Trellix ESM handles packets if the device's capacity is exceeded. In each case, the packet is recorded as an event. You can set up the default policy to operate in alerts only mode or oversubscription mode. You can also view the status of the rule updates and initiate an update.

  1. On the Policy Editor, click the Settings icon GUID-1AC27E71-C030-4273-90E4-91E337946AFF-low.png.

  2. In the Oversubscription Mode field, click Update.

  3. In the Value field, enter the functionality.

    1. Pass (pass or 1) - allows packets that would be discarded to pass unscanned.

    2. Drop (drop or 0) - drops packets that exceed the device's capacity.

    3. To pass or drop a packet without generating an event, enter spass or sdrop.

  4. Click OK.

    Note

    Changing Oversubscription Mode affects the primary and secondary devices (virtual devices). For this change to take effect, you must change the mode on the primary device.