After installation, you can switch from Fanotify to kernel and conversely.
Log on to the system as a user with administrator rights.
Run these commands as required:
To switch from kernel modules to Fanotify - /mfetpcli --usefanotify
To switch from Fanotify to kernel modules - /mfetpcli --usekernelmodule
Restart the Trellix Threat Prevention service.
/opt/McAfee/ens/tp/init/mfetpd-control.sh restartNote
For Red Hat Enterprise Linux 7.x, CentOS 7.x systems, and Oracle Linux 7.x and later, the kernel module is enabled by default. For Ubuntu and SUSE, Fanotify is enabled by default.