If you notice degraded performance in the user interface, try one or more of these remedies.
Set Aggregation to default with Dynamic Aggregation enabled.
Go to the Receiver Properties page and select Event Aggregation.
Make sure that the Aggregation level is set to Medium High (Default).
Note
Dynamic Aggregation is enabled by default in Trellix ESM 10.x and 11.x.
Run scheduled reports during off hours and stagger them so they do not run at the same time.
Go to ESM System Properties and select Reports.
Select the Enabled reports and click Edit for each report.
In the When do you want the report to run section, click Edit Conditions.
Schedule reports to run during nonpeak hours. Run reports at different times.
Verify that devices are configured with the correct DNS server.
From the device Properties page, click <devicce> Management.
Click Interface.
In the Interfaces area, click Setup.
Verify that the DNS server IP addresses are correct.
Check for processes running at 100%.
Connect to the Trellix ESM using SSH.
Enter
htopat the command prompt.Note
Shift+M sorts results by memory use.
Shift+H shows or hides the users.
Shift+P sorts according to the CPU use.
i sets the I/O priority.
Examine the VIRT values (total program size in memory). If the values in the VIRT column are red, collect the device data and open a service request with Trellix Technical Support.
Check for an excessive number of alarms.
On the System Properties page, click Alarms.
Use your best judgment to determine if the number of configured alarms is affecting performance. Consider factors such as number of events, types of alarms, and the cardinality of events.
Delete old triggered alarms.
From the navigation menu
, select Alarms.Right-click alarms that are no longer useful and click Delete.
Set alarms to trigger less frequently.
On the System Properties page, click Alarms.
Select an alarm and click Edit.
Select the Condition tab.
Set the Maximum Condition Trigger Frequency to a value sufficient to reduce the number of alarms to a reasonable level (at least 10 minutes).
Check for multiple Signature IDs in alarm configuration.
On the System Properties page, click Alarms.
Select an alarm and click Edit.
Select the Condition tab.
Make sure the alarm has only one Signature ID in the Values field.
Restrict insertion of historical data.
From the Receiver Properties page, click Events, Flows, and Logs.
Select Don't insert events older than x days.
Set the value to the lowest reasonable retention (typically 5–7 days).
Make sure future events are not being retrieved.
From the Receiver Properties page, select Receiver Management.
Click Time Delta.
If the Time Delta for the data sources is set to retrieve future events, open a Service Request with Trellix Technical Support to correct this issue.
Check for long-running tasks.
From the System Properties page, select ESM Management.
Select the Maintenance tab and click Task Manager.
Check for tasks that have been running for a long time and close them.
Disable unneeded parsing rules
Select a Receiver from the device tree and open the Policy Editor.
.png)
Click + next to Receiver.
Click Filter and create filters for events you don't need.
Click Advanced Syslog Parser and disable any rules you don't need.
Click Data Source and disable any rules you don't need.
Tune Trellix ESM - ACE correlation rules
Select the ACE from the device tree.
Open the Policy Editor.
.png)
Select Correlation.
Click Advanced in the lower right.
Set Origin to User Defined and refresh the view.
Double-click a rule to open it.
Review the rule logic for efficiency. For example, a correlation rule that has the condition "Not In (IP address list)" must search through a long list of IP addresses, which contributes to poor performance. Use the "In" condition instead.
Turn off Copy Packet
Select a Receiver from the device tree and open the Policy Editor.
.png)
Click + next to Receiver.
Click Advanced Syslog Parser.
Turn off Copy Packet for all rules.
Click Data Source.
Turn off Copy Packet for all rules.
Turn on aggregation.
Select a Receiver from the device tree and open the Policy Editor.
.png)
Click + next to Receiver.
Click Data Source.
Turn on Aggregation for all rules.