The General policy configures core client operations and performance. On this page, you can enable self-protection, manage CPU usage and event storage, and set up logging and communication with Endpoint Security (HX) servers.
Self Protection
Option | Definition |
|---|---|
Enable Self Protection | Self Protection prevents unauthorized tampering with EDRF processes, files, and configurations to maintain product integrity and effectiveness against sophisticated attacks. This option applies to Windows and Linux endpoints.
|
Enable password to uninstall | Requires a password to uninstall the EDRF Client from endpoints.
|
EDR Content Updates
Option | Definition |
|---|---|
Enable Content Updates | Delivers regular threat intelligence and detection signature updates to the endpoint. Default: 240 minutes Range: 60—1440 minutes |
Trellix EDR with Forensics Health
Option | Definition |
|---|---|
Report health status | Reports the operational status of EDRF on endpoints. Default: 10 minutes |
Performance Management
Option | Definition |
|---|---|
Acquisition CPU usage limit | Limits the percentage of CPU the EDRF Client can use to collect endpoint data. Default: 100 percent Range: 10—100 percent |
Event storage | Sets the maximum disk space for security event logs on an endpoint. Default: 120 MB Range: 10—500 MB |
Storage mode | Determines how event data is stored on endpoints. Available modes are Conventional (default), In-Memory, Memory-Mapped, and Memory-Mapped I/O. |
Priority Scheduling | Assigns priority levels to Trellix tasks to ensure critical operations are completed promptly. |
Trellix EDR with Cloud
Option | Definition |
|---|---|
Enable EDR module | Connects ePO with Trellix EDR to enable EDR functionalities. This is enabled by default.
|
Trellix EDR with Forensics Logging
Option | Definition |
|---|---|
Information | Logs general system events, such as startup, shutdown, and configuration changes. |
Debug | Logs detailed troubleshooting information, including function calls and variable values. |
Warning | Logs potential issues that do not necessarily impact system functionality immediately. |
Error | Logs error messages for problems that have occurred, such as failed operations. |
You can generate logs based on event count or calendar days. Additionally, you can configure logs to be stored in separate modules.
Component Logging
Option | Definition |
|---|---|
Calls to libuv read and write | Logs detailed read and write data activity within the libuv library. |
SSL functions | Logs activities related to Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. |
Internal queue usage | Logs information about the internal queues used to process various tasks and events. |
Job-related | Logs activities associated with specific jobs performed by EDRF. |
EDR Service Logging
Option | Definition |
|---|---|
Logger format | Trellix EDR allows you to configure the Logger format in its policies. The main options are:
|
Log level | Controls the detail level for the service log files. The various log levels include:
|
Buffer size | Sets the number of log messages stored in memory before being written to the log file. Default: 20 |
Maximum size of the log | Sets the maximum size for the client service log file. When the limit is reached, the file is archived, and a new one is created. Default: 10 MB |
Forensics (HX) Server
The Forensics (HX) Server setting allows you to select which Endpoint Security (HX) instance an endpoint uses for forensics actions. This feature allows you to configure and manage multiple HX instances within your ePO environment.
Option | Definition |
|---|---|
Poll interval | Sets the poll interval, the standard time between server data checks. Default: 600 seconds |
Fastpoll interval | Sets the fastpoll interval for more rapid server updates. Default: 30 seconds |
Proxy Settings for EDR with Forensics
Option | Definition |
|---|---|
Enable proxy | Enables proxy communication between the EDRF Client and the Endpoint Security (HX) server. You must also select the operating system. |