The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Review filter rules for throttling

Prev Next

To implement throttling, rules that filter and stop observations are added to the Stop Observation Requests rule group.

This rule group is read only and is assigned to the default read-only Throttling Rules policy. Initially, this policy isn't assigned to any system or group. When the number of observations reaches the defined threshold, this policy is applied to My Organization (all systems and groups in your organization).

  1. On the ePO - On-prem console, select Menu → Policy → Policy Catalog.

  2. Select Solidcore 8.x.x: Application Control for the product.

  3. Click the Throttling Rules policy.

  4. From the Rule Groups pane, select Stop Observation Requests.

  5. Select the Filters tab.

  6. Review the listed rules.