Views:

Profile

Endpoints installed with an Apex One as a Service agent and Wireshark to capture all HTTP requests to Apex One as a Service and Trend Micro backend services, including:

  • Server-agent connection for configuration deployment/sync
  • Azure Storage/Global ActiveUpdate (AU) for components update
  • Certified Safe Software Service and Behavior Monitoring whitelist checking queries
  • File Reputation/Web Reputation/Predictive Machine Learning queries
  • Smart Protection Feedback
  • Endpoint Sensor activity data

Result

The average traffic generated by a single Apex One agent per day depends on the features enabled on the product. Please refer to the table below for more information:

SetupUploadUpload
Throughput
DownloadDownload
Throughput
Total
Apex One without Endpoint Sensor feature8.82 MB0.82 Kbps16.59 MB1.54 Kbps25.41 MB
Apex One with enabled Endpoint Sensor feature25.93 MB2.40 Kbps16.59 MB1.54 Kbps42.52 MB
Apex One with XDR Endpoint Sensor feature15.82 MB1.50 Kbps16.59 MB1.54 Kbps32.55 MB

Traffic Breakdown

"Upload" meaning Agent > Apex One server, Apex Central server, and backend services, composed of:

  • Endpoint Sensor activity data
  • Apex server/agent communication, backend service communication, configuration, and logs
ComponentUploadUpload Throughput
EDR Data17.11 MB1.58 Kbps
XDR (Vision One Endpoint Sensor) Data7 MB0.6 Kbps
Apex One Server/Agent communication8.82 MB0.82 Kbps

Upload

"Download" meaning Apex One server, Apex Central server, and backend services > Agent, composed of:

  • Apex server/agent communication, configuration
  • Engine/Pattern update
ComponentDownloadDownload Throughput
Apex One Server/Agent communication12.59 MB1.17 Kbps
Component Update4 MB0.37 Kbps

Upload

Additional Notes and Information

  • This data is collected from the Trend Micro internal beta site and is for reference only. Different environments/feature sets might have different results.
  • This data is subject to change when new features are introduced on Apex One as a Service updates.
  • Bandwidth consumption can be reduced by setting up Update Agents, which can act as distribution points for product and pattern updates.
  • To distribute the task of deploying components, domain settings, or agent programs and hotfixes to Security Agents, assign some Security Agents to act as Update Agents, or update sources for other Security Agents. This ensures that Security Agents receive updates in a timely manner without directing a significant amount of network traffic to the Apex One server.