By default, the NDR retrieves metadata from the Endpoint Security Server every 30 minutes by default and the Server retrieves data from Agents every 30 minutes. For information about configuring your Server's polling frequency, see the "Configuring Automatic Triage Settings". Trellix recommends configuring your NDR to index metadata from the Server every 90 minutes in order to capture the most recent information without overwhelming NDR. If the NDR indexes data from the Server too frequently, you may experience significant performance issues. The indexing rate can be configured after you pair the two appliances.
You can also change Endpoint Security Server credentials and SSL verification after integration.
Note
The IP address of a paired Endpoint Security Server cannot be changed after integration. If an incorrect IP address has been integrated with the NDR, Trellix recommends deleting the device and re-adding it with the appropriate IP address.
To configure the indexing using CLI:
Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemEnter the HX configuration menu:
npadmin@ia (config)# hx-gwYou see the following menu:

Edit an existing server configuration:
EEach paired HX is assigned a number that appears above its IP address in the HX Server Configuration menu. Enter the index of the paired HX you want to edit. For example, if you only have one paired HX appliance, enter 1.
The Edit Device Configuration menu appears:

Enter your choice and edit the configuration. Press enter to apply your change.
Enter
Xto save your changes.