The Maximum Cache Size setting controls the maximum number of unique events the endpoint will hold in its cache before older events are removed. This setting directly affects the memory footprints of the endpoint for the Logon Tracker process. The default cache size is 5,000,000 unique events. Roughly each event requires 300 bytes of storage in the cache. 5,000,000 events will require 1.5 GB of memory.
Maximum cache size
- Published on Sep 11, 2026
- 1 minute(s) read
Was this article helpful?
Related articles
- Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Maintaining your systems > Maintaining your system in an unmanaged environment > Review changes using events
- Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.3.x - Windows Product Guide > PG - MCC-MAC - Maintaining your systems > Maintaining your system in an unmanaged environment > Review changes using events
- Application Control and Change Control > Application and Change Control 6.x > Trellix Application and Change Control 6.6.x - Linux Product Guide > Maintaining your systems > Maintaining your system in an unmanaged environment > Review changes using events