- What data is sent to the ePO - On-prem server and what is sent to the database?
A data channel is a mechanism for Trellix products to exchange messages between their endpoint plug-ins and their management extensions. The data channel provides most data sent from the Agent Handler to the application server. It is used internally by the ePO - On-prem server for agent deployment and wake-up progress messaging. Other functions such as agent properties, tagging, and policy comparisons are performed directly against the ePO - On-prem database.
- If the ePO - On-prem server is not defined in my repository list, does replication still occur?
Yes, if the agent contacts the Agent Handler for software packages, the Agent Handler retrieves them from the ePO - On-prem server Main Repository.
- How much bandwidth is used for communication between the database and the Agent Handler?
Bandwidth between the Agent Handler and the database varies based on the number of agents connecting to that Agent Handler. But, each Agent Handler places a fixed load on the database server for:
Heartbeat (updated every minute)
Work queue (checked every 10 seconds)
Database connections held open to the database (two connections per CPU for EventParser plus four connections per CPU for Apache)
- How many agents can one Agent Handler support?
Agent Handlers for scalability are not required until a deployment reaches 100,000 nodes. Agent Handlers for topology or failover might be required at any stage. A good rule is one Agent Handler per 50,000 nodes.
- What hardware and operating system should I use for an Agent Handler?
Use the Microsoft Server Operating System (2008 SP2+ server or 2012 64-bit server).
Note
Non-server Operating System versions have severe (~10) limits set on the number of incoming network connections.
Frequently asked questions
- Published on Sep 7, 2026
- 1 minute(s) read
Was this article helpful?