Defining the maximum thresholds for network database and file hash database

Prev Next

The maximum size of your network and file hash databases affects the network flow, file hash, and trace events. You can use Trellix EDR to maintain the size of your network and file hash databases based on a configured value.

Managing network database

In a network database, when the database size exceeds the Max database size (MB) specified in the Network Flow policy, older rows are deleted. This cleanup task is performed every hour, by default. Between a cleanup task and the next cleanup, the database size can increase.

Increase in network activity on a device can also increase the database size rapidly between cleanups. For web servers, you might already know about the size increase in advance. The increase can be due to a process that generates a large amount of data when connected to the network. In such scenarios, to keep the database size from exceeding the limit, you can add the process name to Ignore Process for collection of TCP/UDP information - (Use ';' as separator)(Windows only).

Managing file hash database

A file hash database stores the list of files and attributes in the system. It contains existing files and some deleted files. When the database size exceeds Max database size (MB) specified in the File Hashing policy, Trellix EDR removes only the rows of deleted files.

If a device has numerous files, the file hash database size appears more than the limit specified in the policy. Trellix EDR can't remove the entries in the database as these entries can be linked to a file in the file system.Trellix EDR doesn't have visibility whether the entries belong to a deleted file. The limit specified in the file hash database is an indication to start removing the deleted files that are in the database. To prevent the database size from exceeding the limit, you can add these extensions or paths to the ignored lists in the policy:

  • Ignore Files on Windows - (Use ';' as separator)

  • Ignore Extensions on Windows (Use ';' as separator)

  • Ignore Paths on Windows (Use ';' as separator)

Note

All extension path exclusions are case insensitive and Trellix EDR now supports per-directory case sensitivity.

Example 1

Assume that Max database size (MB) for File Hashing policy is set to 60 MB. The entries for the current files (that exist in the file system) occupy 50 MB. The remaining 10 MB in the database are for storing the entries for deleted files in the file system.



Example 2

Assume that Max database size (MB) for File Hashing policy is set to 60 MB. The entries for the current files (that exist in the file system) occupy 200 MB because the device has numerous files. As a result, there is no space reserved for the deleted files. But, Trellix EDR retains the entries for deleted files up to 30 days.



Max database size (MB) and Max database size %

There are two options for configuring the network and file hash database size thresholds: Max database size (MB) and Max database size %. If Max database size (MB) is set to a size in MB, Trellix EDR uses it as the defined threshold. If Max database size (MB) is set to 0 (zero), Trellix EDR uses the percentage threshold. This percentage is calculated based on the disk, where Trellix EDR is installed, for example,C:\.

You can also disable a feature if you don't want a specific capability in the server. For example, if you don't want the network sniffing feature, you can disable the Enable Network Sniffing option.