Best practice: SuperAgent repositories

Prev Next

You can create a SuperAgent repository to act as an intermediary between the server and other agents.

The SuperAgent caches information received from a ePO - On-prem server, the Main Repository, or a mirrored Distributed Repository, and distributes it to the nearest agents. The Lazy Caching feature allows SuperAgents to retrieve data from ePO - On-prem servers only when requested by a local agent node. Creating a hierarchy of SuperAgents along with lazy caching further saves bandwidth and minimizes the wide-area network traffic.

A SuperAgent also broadcasts wake-up calls to other agents using that SuperAgent repository. When the SuperAgent receives a wake-up call from the ePO - On-prem server, it wakes up the agents using its repository connection.

Note

This is an alternative to sending ordinary wake-up calls to each agent in the network or sending an agent wake-up task to each computer.

For detailed information about SuperAgents and how to configure them, see the Trellix Agent Product Guide.

SuperAgent repositories

Use systems hosting SuperAgents as distributed repositories. SuperAgent repositories have several advantages over other types of distributed repositories:

  • Folder locations are created automatically on the host system before adding the repository to the repository list.

  • SuperAgent repositories don’t require additional replication or updating credentials — account permissions are created when the agent is converted to a SuperAgent.

    Tip

    Although functionality of SuperAgent broadcast wake-up calls requires a SuperAgent in each broadcast segment, broadcast wake-up calls are not a requirement for the SuperAgent repository. But, managed systems must have access to the system hosting the repository.

SuperAgent considerations

When you configure systems as SuperAgents, follow these guidelines.

  • Use existing file repositories in your environment, for example Microsoft System Center Configuration Manager (SCCM).

  • You don't need a SuperAgent on every subnet.

  • Turn off Global Updating to prevent unwanted updates of new engines or patches from the Main Repository.

SuperAgent and its hierarchy

A hierarchy of SuperAgents can serve agents in the same network with minimum network traffic utilization. A SuperAgent caches the content updates for the ePO - On-prem server or distributed repository and distributes content updates to the agents in the network, reducing the wide area network traffic. It is always ideal to have more than one SuperAgent to balance the network load.

You use the Repository policy to create the SuperAgent hierarchy. We recommend that you have a three-level hierarchy of SuperAgents in your network.

See Trellix Agent Product Guide for details about creating a hierarchy of SuperAgents, SuperAgent caching (lazy caching), and communication interruptions.

Create a SuperAgent

Creating a SuperAgent requires these tasks.

  1. Create a new SuperAgents policy.

  2. Create a new group in the System Tree, for example named SuperAgents

  3. Assign the new SuperAgent policy to the new SuperAgents group.

  4. Drag a system into the new SuperAgents group.

Once you have created the new SuperAgents group, you can drag any system into that group and it becomes a SuperAgent the next time it communicates with the ePO - On-prem server.