The HX appliance issues warnings if the installed security content becomes outdated. This feature helps to ensure that Trellix appliances—offline appliances in particular—do not use outdated security content. By regularly downloading and installing the latest security content, you minimize false negative and false positive results.
This feature is supported in Endpoint Security (HX) software release 3.3 and later.
The security content timestamp
The security content creation date is indicated by a timestamp embedded in the security content metadata.
In the appliance Web UI, the timestamp of the installed security content is displayed in the Content Version panel of the About page.
.png)
In the appliance CLI, the timestamp of the installed security content is displayed in the Timestamp (UTC) field of the show fenet security-content status command output. This timestamp is also displayed in the Web UI and the CLI command output of the managing Central Management System appliance. See the Central Management System Administration Guide.
Warnings for outdated security content
The appliance periodically checks the age of the installed security content by comparing its system clock time to the timestamp embedded in the security content metadata. When security content is more than 336 hours (14 days) old, the show fenet security-content status command output includes a warning message.
Email is sent to recipients who are configured to receive notifications for failure-level system events, provided that automatic security content updates are enabled.
The Web UI displays a warning message at the top of the Dashboard.
The output of a CLI command includes a warning message.