Performing periodic maintenance is important to ensure proper ePO - On-prem server operations. Performing every task daily, weekly, or monthly, is not required. But periodic tasks are important to ensure that overall site health, security, and disaster recovery plans are up to date.
Note
Create a periodic maintenance log to document dates that maintenance was conducted, by whom, and any maintenance-related comments about the task conducted.
Task | Description |
|---|---|
Assess your environment, policies, and policy assignments periodically to confirm that they are still applicable. | Organizational needs can change. Periodically review both existing policies and policy assignments to ensure that they still make sense in the environment. Fewer policies simplify server administration. |
Review existing client tasks and task assignments periodically to confirm that they are still needed. | Client tasks run scans, deploy product updates, product patches and hotfixes, and more to systems managed by ePO - On-prem. Clean out unused tasks to reduce system complexity which can ultimately affect database size. |
Review existing tags and tag criteria to ensure that they are still relevant to your environment. | Use tags as an alternative to System Tree groups to combine, or select a group of systems to operate on. For example, to send updates, deploy Trellix managed products, or run scans. Tagging is useful, but you must monitor tags to ensure that they are useful and have the impact needed. |
Review product exclusions (for example, Threat Prevention) and includes/excludes (for example, Access Protection rules) periodically to validate relevancy. | You must keep exclusions as specific as possible in your environment. Products changes can affect the exclusions that you have configured. Periodically review exclusions to ensure that they still accomplish what is needed. Plus, you can use High and Low Risk OnAccess scanning configurations to augment exclusions. Structure the System Tree, or use tags as another method to control exclusions. |
Make any hardware changes or remove any repositories that you want to decommission. | As your network and organization changes, you might find that changing the location and type of repositories you use provides more efficient and effective coverage. |
Validate that you have the required software, such as the latest version of the Trellix Agent. | Always use the most current version of Trellix managed products to ensure that you have technical support for those products. Plus, you have the latest features and fixes available. |
Remove any unsupported software or software for products you aren't using from the main and distributed repositories. | Keeps disk space to a minimum and removes clutter from the ePO - On-prem server and distributed repositories. Only keep those products currently in use in your environment in the Main Repository. |
Validate your System Tree and remove any agents that have not communicated with the ePO - On-prem server in 30 days or that are de-commissioned. | Keep the System Tree organized and delete systems that are no longer in use, or reporting to ePO - On-prem. A clean System Tree ensures that reports do not contain extraneous information. Set up a server task to delete inactive systems. |
Remove server tasks that are no longer used. | Keep only those server tasks that you intend to use in the task listing. You can always disable an unused task that you want to keep, but don't use regularly. Keeping a minimum list of tasks that you use regularly reduces ePO - On-prem complexity. |
Remove Automated Responses that are no longer relevant. | Automated responses are configured to alert individuals, particularly system administrators; when malware event threats, client treats, or compliance issues must be resolved. |
Delete shell systems using a ePO - On-prem server task. | Delete systems with incomplete or missing system and product properties from the System Tree. Those systems skew reports and queries, and waste space in the ePO - On-prem database. |
Monitor database size | Check the size of the ePO - On-prem database and determine whether, and how often, to purge events reported to ePO - On-prem. See How to identify why the ePolicy Orchestrator database is large, KB76720. To purge events from the database, see How to remove old events and shrink the ePolicy Orchestrator - On-premises database, KB68961 and how to purge the Audit Log, Server Task Log, and Threat Event Log. |