Enabling and Disabling Real-Time Indicator Detection

Prev Next

By default, real-time indicator detection is turned on (enabled) for all of your host endpoints through the agent default policy. However, if it has been disabled, you can use the Web UI or the API to modify the agent default policy and enable real-time indicator detection for all of your host endpoints. You can also use the Web UI or the API to create or modify a custom policy that enables real-time indicator detection processing and assign the custom policy to one or more host sets in your enterprise.

This section covers how to use the Web UI to enable and disable real-time indicator detection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your real-time indicator detection policies.

Important

On hosts with a high number of events, some events may not be recorded.