Enable and disable modules in ePO

Prev Next

After installing and enabling the modules in the Forensics workspace, you must enable them in the ePO Policy Catalog. This creates and enforces the policy that activates the EDRF Client on your managed endpoints. Once the policy is applied, the client begins collecting forensic data and streaming it to the Endpoint Security (HX) server. All protection and remediation capabilities also become fully operational as defined in your policy.

To enable the modules and enforce the policy:

  1. Log in to your Trellix ePO environment as an administrator.

  2. Navigate to MenuPolicyPolicy Catalog and then select Trellix EDR with Forensics.

  3. To enable Process Tracker and Logon Tracker, expand the Streaming category.

    1. Click the name of the policy you want and select Edit action.

    2. Enable Logon Tracker and Process Tracker in their respective settings.

      For more information on additional Logon Tracker settings, see EDRF Policy Catalog.

  4. To enable Host Remediation, expand the Remediation category.

    1. Click the name of the policy you want and select Edit action.

    2. Enable Host Remediation.

  5. Click Save.