The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable or disable Fanotify and kernel modules

Prev Next

After installation, you can switch from Fanotify to kernel and conversely.

  1. Log on to the system as a user with administrator rights.

  2. Run these commands as required:

    • To switch from kernel modules to Fanotify - /mfetpcli --usefanotify

    • To switch from Fanotify to kernel modules - /mfetpcli --usekernelmodule

  3. Restart the Trellix Threat Prevention service.

    /opt/McAfee/ens/tp/init/mfetpd-control.sh restart

    Note

    For Red Hat Enterprise Linux 7.x, CentOS 7.x systems, and Oracle Linux 7.x and later, the kernel module is enabled by default. For Ubuntu and SUSE, Fanotify is enabled by default.