Enabling and Disabling Real-Time Indicator Detection

Prev Next

By default, real-time indicator detection is turned on (enabled) for all of your host endpoints through the agent default policy. However, if it has been disabled, you can use the Web UI or the API to modify the agent default policy and enable real-time indicator detection for all of your host endpoints. You can also use the Web UI or the API to create or modify a custom policy that enables real-time indicator detection processing and assign the custom policy to one or more host sets in your enterprise.

This section covers how to use the Web UI to enable and disable real-time indicator detection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your real-time indicator detection policies.

Important

On hosts with a high number of events, some events may not be recorded.

Enabling Real-Time Indicator Detection for All Host Endpoints

To enable the real-time indicator detection on all host endpoints:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Toggle the Real-Time Indicator Detection ON/OFF switch to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  6. Click Save.

Note

Enabling real-time indicator detection launches the following process:

/opt/fireeye/bin/rte-sensor

See Real-Time Indicator Detection Sensor for additional features of the rte-sensor process.

Enabling Real-Time Indicator Detection for Selected Host Sets

To enable the real-time indicator detection on select host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the link for the custom policy you want to modify.

  4. Click the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Toggle the Real-Time Indicator Detection ON/OFF switch to ON to enable real-time indicator detection.

  6. Click Save.

    Policy_RTID_Enable.png

Note

Enabling real-time indicator detection launches the following process:

/opt/fireeye/bin/rte-sensor

See Real-Time Indicator Detection Sensor for additional features of the rte-sensor process.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling Real-Time Indicator Detection for All Host Endpoints
To disable real-time indicator detection for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the custom policy you want to modify and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Toggle the Real-Time Indicator Detection ON/OFF switch to OFF to disable real-time indicator detection.

    Policy_RTID_Disable.png
  6. Click Save.

Disabling Real-Time Indicator Detection for Selected Host Sets

To disable real-time indicator detection for selected host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the custom policy you want to modify and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Toggle the Real-Time Indicator Detection ON/OFF switch to OFF to disable real-time indicator detection.

    Policy_RTID_Disable.png
  6. Click Save.