Excluding Host Sets from Real-Time Indicator Detection

Prev Next

By default, real-time indicator detection is turned on (enabled) for all of your host endpoints. If you want to disable this feature for one or more host sets, you can create a custom policy using the Web UI or the API that excludes selected host sets from real-time indicator detection scanning.

This section covers how to use the Web UI to create a custom policy that excludes host sets from real-time indicator detection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your real-time indicator detection policies.

To exclude selected host sets from real-time indicator detection:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

  4. Enter a policy name in the Name field and a policy description in the Description field.

  5. Click Categories to access a list of the policy categories.

  6. Select the Real-Time Indicator Detection checkbox and click Apply.

  7. Toggle the Real-Time Indicator Detection switch OFF to completely disable this feature.

    Policy_RTID_Disable.png
  8. Click Save.

After you create a custom policy that disables real-time indicator detection, you can use the steps outlined in Assigning Host Sets to Agent Policies to assign specific host sets to your custom policy. This will disable real-time indicator detection for all of the selected host sets.