The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Advanced malware scanning timeout options

Prev Next

All the advanced malware engines described above are designed to function based on certain parameters. These parameters are listed below:

  • Packet hold timeout — This is the 6-second period per file for which the Sensor holds the last packet of the file before forwarding it through the egress port. The Sensor holds this packet until there is a report from all the configured malware engines. After this timeout, the Sensor takes the corresponding response action based on the results from those engines that responded within this timeout. If none of the engines responded within this timeout, the Sensor forwards the last packet without taking the response actions (block or TCP reset).

  • File session timeout — This is the 5-minute period that the Sensor waits for a file to download. If the file download exceeds this time interval, the Sensor does not enforce the Advanced Malware policy for that file.

  • File scan timeout — This is the time period for which the Sensor honors results from the configured malware engines. Any update from the engines after this time period are ignored. If Trellix IPS Analysis or Save File is configured, then the file scan timeout is 90 seconds from when the Sensor sent the file to the configured engines. If Trellix IPS Analysis or Save File is not configured, then it is 30 seconds.

Note

File extraction does not work when HTTP response is chunk encoded or Gzip compressed.