If a program is configured as an updater, it can install new software and update existing software. You can add, edit, or remove updaters.
Task
-
Manage updaters in rule groups.
- On the Trellix ePO - On-prem console, select Menu → Configuration → Solidcore Rules.
- Locate the rule group and under Actions, click View.
- On the Updater Processes tab, you can Add, Edit, or Remove an updater.
-
Manage updaters in policies.
- On the Trellix ePO - On-prem console, select Menu → Policy → Policy Catalog.
- On the Policy Catalog page, select the product and category from the list.
- Click the selected policy.
-
Complete the addition of an updater to a rule group or policy.
- On the Updater Processes tab, click Add.
-
Enter the location of the file.
If you add the updater by name, the updater is not authorized automatically. The file must be added to the whitelist.
- Specify an identification updater label for the program.
-
Specify conditions that the file must meet to run as an updater.
- Select condition None to allow the file to run as an updater without any conditions.
- Select condition Parent to allow the file to run as an updater only if it is started by the specified parent.
-
When adding an updater by name, indicate whether to disable inheritance for the updater.
For example, if Process A (that is set as an updater) starts Process B, disabling inheritance for Process A makes sure that Process B does not become an updater.
- When adding an updater by name, indicate whether to suppress events generated for the actions performed by the updater. Typically, when an updater changes a protected file, a File Modified event is generated for the file. If you select this option, no events are generated for changes made by the updater.
- Click OK.