For applications with high file I/O usage, there maybe some performance impact when inline scanning mode is used using Fanotify. To resolve this, enable OAS Deferred Scan to make sure read operations are scanned without any impact on the performance.
Note
Deferred scan is applicable only for Fanotify based systems.
When you enable OAS Deferred scan, scan on read is deferred. Be default, Trellix Endpoint Security (ENS) for Linux only defers Scan on write mode.
You can enable deferred scan using the installer option sudo ./install-mfetp.sh usedeferredscan or command line interface option.