Administration configuration reference
This page lists every setting on the Administration → Configuration page in MetaDefender NDR. It tells you what each setting does, the default value, the allowed values, and when a change needs a restart. Use this page as the reference for day-to-day configuration.
This page is for the customer administrator who manages a MetaDefender NDR deployment. It assumes an installed Manager, at least one adopted sensor, and an administrator account. For the layout of the Administration area, see the Administration overview. For host-level Manager settings, see Manager configuration.
Abbreviations
This page expands each abbreviation at first use. The full list follows:
CA — certificate authority
C2 — command-and-control
DGA — domain generation algorithm
DNS — Domain Name System
ICAP — Internet Content Adaptation Protocol
IP — Internet Protocol
ML — machine learning
MIME — Multipurpose Internet Mail Extensions
NTP — Network Time Protocol
OIDC — OpenID Connect
RCF — Random Cut Forest
SAML — Security Assertion Markup Language
SIEM — security information and event management
SMTP — Simple Mail Transfer Protocol
SSO — single sign-on
TLS — Transport Layer Security
URL — Uniform Resource Locator
Before you begin
You need the administrator role. The Configuration page is available only to administrators.
Open the page at Administration → Configuration.
A setting marked Sensitive holds a secret, such as a password or an API key. The page does not show the current value.
A setting marked Restart needed takes effect only after the service restarts.
How settings are scoped
The Configuration page groups settings into four scopes:
System settings (global) — settings for the whole system.
Enrichment and detection settings (global) — settings for the enrichment and detection services.
Manager settings (per host) — settings for one Manager host.
Sensor settings (per sensor) — settings for one sensor.
A global setting applies to every sensor. A per-host or per-sensor setting applies to one target only. Set a per-host or per-sensor value for each target that needs a different value.
How to read the setting tables
Each setting table has these columns:
Setting — the label on the page. The configuration key follows in code font.
What it does — the function of the setting.
Default — the default value.
Allowed values — the type, the list of choices, or the number range.
Notes — flags for required, sensitive, or restart-needed settings.
Configuration sections
Each section below is its own page. Select a section to see its settings.