This command is specific to Trellix IPS Sensors and all REST channel submissions. Use this command to prevent Sensors from sending unsupported file types to for analysis.
Syntax:
samplefilter <status><enable><disable>
Parameter | Description |
|---|---|
status | displays whether the sample filtering feature is enabled or disabled currently. By default, it is enabled. |
enable | sets the sample filtering on. When it is enabled, considers only the supported file types from Trellix IPS for analysis. ignores all other file types and also informs Trellix IPS that a sample is of an unsupported file type . This prevents resources being spent on unsupported file types on both and Trellix IPS. |
disable | sets the sample filtering to off. When disabled, considers all the files submitted by Trellix IPS for analysis but only the supported file types are analyzed. The remaining are reported as unsupported in the Analysis Status and Analysis Reports pages. |
Example:
samplefilter status