The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

When is the cache flushed?

Prev Next

Rule configuration defines when to flush the entire cache. Object state, reputation, or expiration date defines when to flush individual objects in the cache.

The whole Adaptive Threat Protection cache is flushed when the rule configuration changes:

  • The state of one or more rules has changed, for example from Enabled to Disabled.

  • The rule set assignment has changed, such as from Balanced to Security.

An individual file or certificate cache is flushed when:

  • The file has changed on the disk.

  • The TIE server publishes a reputation change event.

  • The object expires.

    By default, items in the cache are flushed between 1 hour and 1 week, depending on type and reputation.

    Sometimes, the expiration time for an item might differ from the default.

    • The cache is full.

      Recently accessed cache items are retained; older items expire and are removed.

    • Time to live is set in the AMCore Content file or by the reputation provider.

    • Connection status in effect when the object was added to the cache.

      If an object was added when the reputation provider was not connected to the TIE server or Trellix GTI, the reputation is updated when connectivity is restored.

After the item is flushed from the cache, the next time Adaptive Threat Protection receives notice for the file, the reputation is recalculated.