Administration configuration reference

This page lists every setting on the Administration → Configuration page in MetaDefender NDR. It tells you what each setting does, the default value, the allowed values, and when a change needs a restart. Use this page as the reference for day-to-day configuration.

This page is for the customer administrator who manages a MetaDefender NDR deployment. It assumes an installed Manager, at least one adopted sensor, and an administrator account. For the layout of the Administration area, see the Administration overview. For host-level Manager settings, see Manager configuration.

Abbreviations

This page expands each abbreviation at first use. The full list follows:

  • CA — certificate authority

  • C2 — command-and-control

  • DGA — domain generation algorithm

  • DNS — Domain Name System

  • ICAP — Internet Content Adaptation Protocol

  • IP — Internet Protocol

  • ML — machine learning

  • MIME — Multipurpose Internet Mail Extensions

  • NTP — Network Time Protocol

  • OIDC — OpenID Connect

  • RCF — Random Cut Forest

  • SAML — Security Assertion Markup Language

  • SIEM — security information and event management

  • SMTP — Simple Mail Transfer Protocol

  • SSO — single sign-on

  • TLS — Transport Layer Security

  • URL — Uniform Resource Locator

Before you begin

  • You need the administrator role. The Configuration page is available only to administrators.

  • Open the page at Administration → Configuration.

  • A setting marked Sensitive holds a secret, such as a password or an API key. The page does not show the current value.

  • A setting marked Restart needed takes effect only after the service restarts.

How settings are scoped

The Configuration page groups settings into four scopes:

  1. System settings (global) — settings for the whole system.

  2. Enrichment and detection settings (global) — settings for the enrichment and detection services.

  3. Manager settings (per host) — settings for one Manager host.

  4. Sensor settings (per sensor) — settings for one sensor.

A global setting applies to every sensor. A per-host or per-sensor setting applies to one target only. Set a per-host or per-sensor value for each target that needs a different value.

How to read the setting tables

Each setting table has these columns:

  • Setting — the label on the page. The configuration key follows in code font.

  • What it does — the function of the setting.

  • Default — the default value.

  • Allowed values — the type, the list of choices, or the number range.

  • Notes — flags for required, sensitive, or restart-needed settings.

Configuration sections

Each section below is its own page. Select a section to see its settings.

System settings

Enrichment and detection settings

Manager settings

Related documentation