Allowing increased detection for managed appliances using the Web UI

Prev Next

Use the Appliance Settings: Increased Detection page to select options for sending additional information to Trellix for analysis to increase detection rates. These options, which Trellix recommends, are disabled by default. The settings are applied globally to managed appliances running Release 7.8.0 or later.

Note

See your Trellix sales representative for more information.

CM_IncreasedDetectionSetting_scap.PNG
To allow increased detection:
  1. Click Settings and then select Appliance Settings.

  2. Click Increased Detection.

  3. Select the Suspicious metadata checkbox to send metadata your appliance flags as "likely suspicious" to Trellix for analysis. This may result in more false positives, but will also increase detection rates for actual malware. If you do not select this option, then only metadata flagged as "malicious" will be sent to Trellix.

  4. Select the Suspicious file checkbox to send files that your appliance flags as "likely malicious" to Trellix for analysis. This may result in more false positives being sent to Trellix for analysis, but will also increase detection rates for actual malware.

  5. Click Apply.

Note

Alternatively, you can click a link on the Central Management System Dashboard to open a dialog box with the same options. After you select the options, the link is no longer displayed.