The update_interval key specifies the interval, in seconds, at which malware definition updates should be retrieved from the Trellix servers. Valid values range from 60 seconds to 86400 seconds (one day). The default is 14400 seconds (four hours).
Change this setting using one of the following methods:
Web UI (see ).
API custom configuration channels (see Using API Custom Configuration Channels.
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).