General policy

Prev Next

The General policy configures core client operations and performance. On this page, you can enable self-protection, manage CPU usage and event storage, and set up logging and communication with Endpoint Security (HX) servers.

Self Protection

Option

Definition

Enable Self Protection

Self Protection prevents unauthorized tampering with EDRF processes, files, and configurations to maintain product integrity and effectiveness against sophisticated attacks. This option applies to Windows and Linux endpoints.

Note

On Linux endpoints using the BTRFS file system such as OpenSUSE and SLES, Self Protection does not cover file and folder protections. Service protection remains fully functional on these systems.

Tip

We recommend always enabling this option.

Enable password to uninstall

Requires a password to uninstall the EDRF Client from endpoints.

Note

This option is enabled only for Windows endpoints.

EDR Content Updates

Option

Definition

Enable Content Updates

Delivers regular threat intelligence and detection signature updates to the endpoint.

Default: 240 minutes

Range: 60—1440 minutes

Trellix EDR with Forensics Health

Option

Definition

Report health status

Reports the operational status of EDRF on endpoints.

Default: 10 minutes

Performance Management

Option

Definition

Acquisition CPU usage limit

Limits the percentage of CPU the EDRF Client can use to collect endpoint data.

Default: 100 percent

Range: 10—100 percent

Event storage

Sets the maximum disk space for security event logs on an endpoint.

Default: 120 MB

Range: 10—500 MB

Storage mode

Determines how event data is stored on endpoints. Available modes are Conventional (default), In-Memory, Memory-Mapped, and Memory-Mapped I/O.

Priority Scheduling

Assigns priority levels to Trellix tasks to ensure critical operations are completed promptly.

Trellix EDR with Cloud

Option

Definition

Enable EDR module

Connects ePO with Trellix EDR to enable EDR functionalities. This is enabled by default.

Note

Disabling this feature prevents access to all EDR workspace functions.

Trellix EDR with Forensics Logging

Option

Definition

Information

Logs general system events, such as startup, shutdown, and configuration changes.

Debug

Logs detailed troubleshooting information, including function calls and variable values.

Warning

Logs potential issues that do not necessarily impact system functionality immediately.

Error

Logs error messages for problems that have occurred, such as failed operations.

You can generate logs based on event count or calendar days. Additionally, you can configure logs to be stored in separate modules.

Component Logging

Option

Definition

Calls to libuv read and write

Logs detailed read and write data activity within the libuv library.

SSL functions

Logs activities related to Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols.

Internal queue usage

Logs information about the internal queues used to process various tasks and events.

Job-related

Logs activities associated with specific jobs performed by EDRF.

EDR Service Logging

Option

Definition

Logger format

Trellix EDR allows you to configure the Logger format in its policies. The main options are:

  • None: Stops Trellix EDR from creating service logs.

  • File: This is the common and recommended option, where logs are written to local files on the endpoint.

Log level

Controls the detail level for the service log files. The various log levels include:

  • Debug: Logs detailed information to identify problems with client execution.

  • Trace: Logs detailed information, including method entry/exit and variable values.

  • Info: Logs messages about the progress of the client service. This is the default level.

  • Warning: Logs information about potentially harmful situations.

  • Error: Logs critical error events that prevent the service from running.

Buffer size

Sets the number of log messages stored in memory before being written to the log file.

Default: 20

Maximum size of the log

Sets the maximum size for the client service log file. When the limit is reached, the file is archived, and a new one is created.

Default: 10 MB

Forensics (HX) Server

The Forensics (HX) Server setting allows you to select which Endpoint Security (HX) instance an endpoint uses for forensics actions. This feature allows you to configure and manage multiple HX instances within your ePO environment.

Option

Definition

Poll interval

Sets the poll interval, the standard time between server data checks.

Default: 600 seconds

Fastpoll interval

Sets the fastpoll interval for more rapid server updates.

Default: 30 seconds

Proxy Settings for EDR with Forensics

Option

Definition

Enable proxy

Enables proxy communication between the EDRF Client and the Endpoint Security (HX) server. You must also select the operating system.