Defining the Resource Use Exception Policy

Prev Next

You can create a custom policy to define the resource use exception policy.

Note

The host sets to which the resource use exceptions apply can only be identified using the Web UI.

The exception policy is ignored for any hosts running Trellix Endpoint Security (HX) xAgent versions earlier than version 20.

Setting the Exception Policy Maximum CPU Limit

You can specify the maximum CPU limit for select host sets in your environment by creating a custom policy in the Web UI to define your exception resource use policy

Note

Real-time collection is excluded from CPU limiting.

To define the maximum CPU limit for your custom exception policy:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

    UI_Policy_Custom_Create.png
  4. Enter a policy name in the Name field and a policy description in the Description field.

  5. Click CATEGORIES to access a list of the policy categories.

  6. Select the Resource Use checkbox and click Apply.

  7. In the Resource Use section, specify the percentage of CPU that agents in the selected host sets can use when performing tasks on behalf of the Endpoint Security (HX) server in the CPU use field. Valid values range from 10 through 100 percent.

    Policy_RU_CPU.png
  8. Click SAVE.

  9. Toggle the policy Enabled/Disabled switch to Enabled to activate the new policy.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Setting Automatic Triage Exclusion

You can specify which hosts in a custom policy should be excluded from the automatic collection of triage data when an alert occurs on a host. Auto triage is enabled by default for all hosts in a custom policy.

To enable automatic triage in a custom policy:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

    UI_Policy_Custom_Create.png
  4. Enter a policy name in the Name field and a policy description in the Description field.

  5. Click the CATEGORIES to access a list of the policy categories.

  6. Select the Resource Use checkbox and click Apply.

  7. In the Resource Use section, toggle the Auto Triage ON/OFF switch to ON.

    Policy_RU_ATriage_Switch.png
  8. Click SAVE.

  9. Toggle the policy Enabled/Disabled switch to Enabled to activate the new policy.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Setting the exception policy event storage use limit

Event storage is also known as the ring buffer. If the xAgents' events database exceeds the storage specified by this setting, the xAgent rebuilds the database. If the database is corrupt and the attempt to rebuild it fails, the database is restarted and a new, empty events database is created. The old events database is backed up as file events.db.bk. You may need assistance from Trellix Technical Support to extract the data contained in the backup.

You can specify the event storage use limit for select host sets in your environment by creating a custom policy in the Web UI to define your exception resource use policy

To define the event storage use limit for your custom exception policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

    UI_Policy_Custom_Create.png
  4. Enter a policy name in the Name field and a policy description in the Description field.

  5. Click CATEGORIES to access a list of the policy categories.

  6. Select the Resource Use checkbox and click Apply.

  7. In the Resource Use section, specify the number of megabytes of storage that agents in the selected host sets can use for tasks performed on behalf of the Endpoint Security (HX) server in the Event storage field. Valid values range from 10 to 500 MB.

    Policy_RU_EventStorageLimit.png
  8. Click SAVE.

  9. Toggle the policy Enabled/Disabled switch to Enabled to activate the new policy.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Excluding host sets from the concurrent host limit policy

To exclude specific host sets from the concurrent host limit policy defined in the agent default policy, you need to create a custom policy and turn off (disable) the concurrent host limit switch.

To disable the concurrent host limit for select host sets:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

    UI_Policy_Custom_Create.png
  4. Enter a policy name in the Name field and a policy description in the Description field.

  5. Click CATEGORIES to access a list of the policy categories.

  6. Select the Resource Use checkbox and click Apply.

  7. In the Concurrent Host Limit section, toggle the Concurrent Host Limit ON/OFF switch to OFF.

    Policy_RU_Concurrent_Disable.png
  8. Click SAVE.

  9. Toggle the policy Enabled/Disabled switch to Enabled to activate the new policy.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.