The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix DLP Monitor 11.10 Update 4 (11.10.400) Release Notes

Prev Next

The 11.10 Update 4 release includes feature enhancements and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current release.

Rating for 11.10 Update 4 (11.10.400)

The rating defines the urgency for installing this update.

Recommended

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560.

Release details

Release date: August 10, 2023

Release build:

  • Trellix DLP Monitor appliance installation images:

    • For VMware vSphere virtual appliance — Trellix-MS-11.10.400-3662.100.ms.hw10.hdd.ova

    • For hardware appliance — Trellix-MS-11.10.400-3662.100.iso

  • DLP Appliance Management extension — build 11.10.300.103

  • Data Loss Prevention extension — build 11.10.9.6

    Note

    Data Loss Prevention extension 11.10.9 is incompatible with the older appliance versions. Make sure that you upgrade Trellix DLP Appliance to the latest version.

This release updates components that depend on these extensions:

  • Proprietary Linux OS based on CentOS 7

  • Trellix Agent — version 5.7.8

    Note

    Trellix Agent is built into the appliance software and can't be updated through Trellix ePO - On-prem.

  • Appliance Management extension — build 1.3.3.145

  • Common UI extension — build 1.3.0.258 or later

Data Loss Prevention (DLP) Long-Term Support Release

Important - Trellix is enhancing our Trellix DLP release process to better serve our customers' requirements. This is achieved via defining each release as either a Long-Term Support release or Feature Release. Feature release introduces new features; whereas, Long-Term Support (LTS) release allows customers (under tight change control) to maintain a stable Trellix DLP version without changes to functionality and existing features. The LTS release will include only security updates, bug fixes, and some optimization for the existing features by releasing only patches or hotfixes. As is currently the case, these releases will continue to be fully installable packages.

Note

The latest LTS release for Trellix DLP Monitor is version 11.10 Update 4 (11.10.400).

For more information about LTS releases, see KB91807.

Updated platform, environment, or operating system support

For information on supported platforms, environments, and operating systems, see KB87112.

New or changed features

Integrating Trellix DLP Appliances with Microsoft Information Protection (MIP) — To integrate Trellix Data Loss Prevention Appliances with Microsoft Information Protection (MIP) you must have access to both Microsoft Purview Information Protection (called as MIP) and Microsoft Purview compliance portal (called as AIP). Integration of Trellix Data Loss Prevention Appliances with AIP allows you to use the functionalities of AIP including file encryption and data protection:

  • Allows you to integrate Trellix Data Loss Prevention appliances with AIP to act as a decryption proxy client (MIP client) and use valid AIP credentials to decrypt AIP protected files. Trellix Data Loss Prevention Appliances decrypt all data submitted for data protection analysis.

  • Users can apply sensitivity labels to the M 365 documents, PDFs, text files, email, and web uploads to comply with the company policy. You can configure sensitivity labels in AIP for different data protection policies either with encryption or without encryption.

  • You can use Labelinfo in MSIP classifications to support reading MIP label information or metadata in co-authored or auto-save enabled documents.

Underscore in exact data matching (EDM) — Legacy tokenization treats underscore as an alphabet and expects both scanning and indexing documents to match underscore regardless of its position. Starting with this release, underscore in EDM is:

  • Ignored, if a word is surrounded by underscore.

  • Considered as a word separator, if a word contains an underscore in between.

    For example, in the mail ID xxxx_yy@zz.com, underscore is considered as a word breaker, and the mail ID is divided into two tokens, “xxxx” and “yy@zz.com”. An incident is reported even when the sample or scanned document has an underscore anywhere in a word, but the fingerprinted document doesn't.

Note

To apply the change in underscore tokenization, reindex exact data match fingerprint with the EDMTrain tool.

Resolved issues

This release resolves known issues.

For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.10.9 Release Notes.

Important

This release is cumulative and contains fixes from all previous releases.

Appliance resolved issues

DLPN-12583

This release fixes an issue where scanning would timeout when a policy contains proximity conditions and when the sample triggers multiple proximity searches.

DLPN-12595

This release fixes an issue where Trellix DLP Monitor failed to detect Boldon James tag in PDF files.

DLPN-12796

This release fixes an issue where the uncleared temporary files in the /logs system directory causes “Policy corrupted” error, which is shown in the Appliance Management page.

DLPN-12799

This release fixes an issue where the user information is not shown in Web protection incidents when a user name has spaces.

Known issues

In rare unidentified scenarios, emails sent through Trellix DLP Prevent are rejected with a “550 Unable to process e-mail. (Scanning on service failed)” error.

Data Loss Prevention 11.x.x Known Issues (KB89301).