Sets or resets the polling bookmark that reflects the integration status of indicators from the Central Management System appliance. This bookmark is usually managed by the Central Management System appliance. You might need to reset the bookmark to replay old alerts or if a Central Management System appliance was removed and added again.
If you set the polling bookmark to zero (0), the Central Management System appliance downloads all of its alerts to the appliance after the products are integrated.
Syntax
[no] hx server detection inbound bookmark <nnn>
Parameters
no
Resets the polling bookmark to the default (0).
bookmark <nnn>
Specify a Central Management System alert ID for the current polling bookmark. Valid values range from 0 to 18446744073709551615. The default is 0, which downloads all Central Management System IOC data to the Endpoint Security (HX) appliance. Determine what the latest Central Management System alert IDs are by running the show log matching "alert id" command.
Caution
Trellix does not recommend selecting a Central Management System alert ID of 0 because of the resulting performance impact on your Endpoint Security (HX) appliance after the initial integration with the Central Management System appliance.
If you accidentally set the Central Management System alert ID to 0 and you want to delete all or many of the IOCs downloaded from the Central Management System appliance, temporarily change the Endpoint Security (HX) indicator and alert aging threshold in the Web UI to just a few days. The Endpoint Security (HX) appliance automatically deletes IOCs that exceed this threshold. See "Managing Real-Time Indicator Detection" in the Endpoint Security System Administration Guide. Alternatively, manually remove IOCs from the Endpoint Security (HX) appliance using the Indicators page in the Endpoint Security (HX) Web UI.
Example
The following example sets the bookmark ID to 5000:
hostname (config) # hx server detection inbound bookmark 5000
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Endpoint Security (HX): Release 2.6