Configures the limit for YARA matches.
Trellix identifies and reports on the first five (5) matching YARA rules seen for a given file. YARA rules are specific enough that only one or two rules will match malicious samples at any given time; therefore, more than five matches is usually rare. However, Trellix matches up to 5 rules in general, and for the dynamic engine, the rule with the highest weight is matched.
Syntax
yara match limit number
Parameters
number
The number of matches to identify and report. The range is 0-5 and the default is 5.
Example
hostname (config) # yara match limit 2
User role
Admin or Operator
Command mode
Config
Supported appliances
Central Management System: Release 7.5.0
Email Security — Server: Release 7.6.0
Network Security: Release 7.5.0