What is Observe mode?

Prev Next

In Observe mode, Application Control records execution, installation, and removal activities for managed endpoints.

In Observe mode, a file is allowed to execute unless it is banned by a specific rule. All observations generated on an endpoint are sent to the Trellix ePO - On-prem server after agent-server communication intervals (ASCI). When an endpoint is in Observe mode, no Application Control events are generated for the endpoint.

Activating Observe mode involves these high-level steps:

  1. Identifying the staging or test endpoints for deployment.

    If you have multiple types of endpoints in your setup, group similar types of endpoints to roll out Observe mode. This allows you to analyze product impact on each group of endpoints, discover policy groups, and validate the policies that apply to each group of endpoints.

  2. Placing Application Control in Observe mode for a few days and perform day-to-day tasks on the endpoints.

    Note

    Observe mode can only be activated after the endpoint has been solidified once.

    Requests are created based on observations generated for the endpoints. These requests allow you to discover Application Control policy rules for the software installed on the endpoints.

  3. Periodically reviewing and creating rules for the received requests.
  4. Validating the recently added policies by running frequently used workflows. This helps you verify if more requests are received for the applications.
  5. When the number of requests received reduces considerably, exit Observe mode and place the endpoints in Enabled mode.