If a particular version of malware protection indicators causes performance issues or instability, you can roll it back to previously stable content, if available, with the malware protection content backup utility. Content can be rolled back for any Windows, macOS, or Linux host. Content Backup is disabled by default on your host endpoints.
Content backup is available only when signature and heuristic detection is enabled on Endpoint Security (HX) xAgent .
Note
Content backup for the MalwareGuard engine is not supported.
Backup process
Content backup maintains a maximum of two known stable content versions. The older backup is always replaced. Content backup creates a new pair of backup content versions every 72 hours, by the following example schedule:
Time | Backup Content Version (C) |
|---|---|
Day 0 | – |
Day 1 | C0 |
Day 2 | C0 |
Day 3 | C0 |
Day 4 | C0 and C3 |
Day 5 | C0 and C3 |
Day 6 | C0 and C3 |
Day 7 | C3 and C6 |
Rollback process
Important
Because each set of new definitions includes protection against new threats, reverting to an older revision could lead to missed detections.
If the current version of malware protection indicators causes problems, you can add it to a content exclusion list in the malware protection policy. The problematic version will be replaced with a backup version, and it will not be downloaded in future updates.
This section covers how to use the Web UI to enable, disable, and define the Content Exclusion List for unstable content versions. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your Content Exclusion List.