The Update Metadata Aggregation for Local Intelligence option improves the Update Metadata messages processing and reduces the bandwidth utilization.
The Update Metadata Aggregation for Local Intelligence filters interesting updates from metadata messages and summarizes in-memory relevant information, publishing it to TIE Server for processing with a predictive frequency or when any urgent information arrives.
The Update Metadata Aggregation for Local Intelligence is implemented as a Trellix DXL Broker extension and you can enable it from Trellix DXL Topology section in Server Settings in Trellix ePO - On-prem.
When to enable Update Metadata Aggregation for Local Intelligence
Each environment could be unique in configuration and complexity, where you can find complex topologies, multiple Trellix ENS versions installed in different groups of endpoint, and the same for multiple content and rules. This scenario produces that multiple endpoints can publish the same or similar information multiple times or can publish the hash information in multiple messages.
Tip
This situation can arise when some beta rules are enabled.
In consequence, multiple and duplicated messages travel in the Trellix DXL fabric that TIE server needs to process, and it consumes resources and performs unnecessary database searches and writes. This feature improves the Metadata message processing.