The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable or disable Fanotify and kernel modules

Prev Next

After installation, you can switch from Fanotify to kernel and conversely.

  1. Log on to the system as a user with administrator rights.

  2. Run these commands as required:

    • To switch from kernel modules to Fanotify - /mfetpcli --usefanotify

    • To switch from Fanotify to kernel modules - /mfetpcli --usekernelmodule

  3. Restart the Trellix Threat Prevention service.

    /opt/McAfee/ens/tp/init/mfetpd-control.sh restart

    Note

    For Red Hat Enterprise Linux 7.x, CentOS 7.x systems, and Oracle Linux 7.x and later, the kernel module is enabled by default. For Ubuntu and SUSE, Fanotify is enabled by default.