You can use the Network Flow tab to configure the network flow plug-in on monitored devices.
Note
Make sure Enable Plug-in and Enable Network Sniffing are selected on the Network Flow policy page to gather information using the NetworkFlow collector.
Option | Definition |
|---|---|
Enable the Network Flow collector | This option is enabled by default. Enables the NetworkFlow collector capabilities on the device. |
Enable Network Sniffing | This option is disabled by default. When enabled, enables you to configure your network-related activities to a granular level. If this option is disabled, certain network activities that require higher resource consumption such as network triggers and network flow collectors are disabled. This only impacts the real-time search and not the historical trace visibility.
|
Maximum size (MB) of the device storage that can be used by the Network Flow collector | Specifies the size limit for the NetworkFlow collector database on devices. When this limit is reached, older records are discarded from the database. The default value set is 120 MB. The minimum and maximum value you can set is between 0 MB and 8192 MB.
|
Maximum percentage of the device storage that can be used by the Network Flow collector database | Specifies the percentage of device storage that the NetworkFlow collector database can use. The default value set is 2 percentage. The minimum and maximum value you can set is between 1 and 100 percentage. |
Maximum number of results returned by the Network Flow collector | Specifies the maximum number of result rows returned by the NetworkFlow collector. The default value set is 512. The minimum and maximum value you can set is between 64 and 8192. |
Collect TCP/UDP system process information (Windows Only) | This option is disabled by default. When enabled, collects TCP/UDP connection information generated by system processes on devices running Windows. It determines if an application tried to connect to a particular host or IP address. Disabling this option collects only user space application connections. |
Exclude process(es) from collecting TCP/UDP information (Use ';' as separator) (Windows only) | Excludes processes from the NetworkFlow monitoring to reduce resource consumption and performance impact in systems that are web servers.
|
Option | Definition |
|---|---|
Enable the option to display the message on quarantine actions | This option is disabled by default. When enabled, sends notifications to devices when the devices are quarantined. |
Enforce password to unquarantine the Trellix EDR client at endpoint (Windows only) | This option is disabled by default. When enabled, you can set a password that can be used to end the quarantine of an endpoint. When the option is enabled, set a password, and the policy is enforced on endpoints, follow the below steps to end the quarantine of an endpoint:
When the correct password is entered, you can see a successful message on the screen that can be used to end the quarantine of an endpoint. However, this message can be customized. |
Message to display on a device when it is quarantined (max: 3072 characters) | The default notification message that is sent to a device when it is quarantined. This message can be customized. |
Message to display on a device when it is removed from the quarantine (max: 3072 characters) | The default notification message that is sent when the quarantine status is removed from a device. This message can be customized. |
Exclude application paths from quarantine for Windows (Use ';' as separator) (max: 3072 characters) | Excludes application paths including .exe from quarantine for Windows. You can use ';' as separator. |
Exclude application paths from quarantine for macOS (Use ';' as separator) (max: 3072 characters) | Excludes application paths including .exe from quarantine for macOS. You can use ';' as separator. |