Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.1
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Distributed ESM – Trellix ESM 11.6.x and higher does not support environments with Distributed ESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered. Follow the below upgrade process:
Refer to the HA Receiver upgrade process in, Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
New features and changes
This release includes these new features and changes.
Rebranding changes
This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Enterprise Security Manager as usual.
You will notice the following changes in the software:
Product Name - McAfee Enterprise Security Manager is renamed to Trellix Enterprise Security Manager. All features and options prefixed with product name are renamed with the new product name.
Brand logo - McAfee logo is replaced with Trellix logo.
User interface - Color and typeface are updated and provide better user experience.
End User License Agreement and Copyright - The End User License Agreement and Copyright are updated as per legal requirements. Please read the agreement for details.
Updated internally used certificates.
McAfee Event Format is changed to Trellix ESM Event Format.
New features
This release provides support for these features.
UI Migration from Flash to Royale.
Added support for Trellix Email Security.
Added support for Trellix Endpoint Security (HX).
Added support for Trellix Network Security.
Kafka Data Source – Added support to use Kafka as a retrieval method for data sources.
Removed features
This release removes support for these features.
Distributed ESM – Trellix ESM 11.6.x and higher does not support environments with Distributed ESM configurations.
Removed sound support for Alarms.
Removed the DEM, MVM, ELMERC and Distributed ESM from the Add Device wizard options list from the UI.
All McAfee Vulnerability Manager dependent device references are removed from the UI.
All DEM references are removed from the UI.
The ESM Admin application is no longer available for download.
Removed the Alarms and Cases Pane feature for all users.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Data Source Management | SIEM-35231 | Fixed an issue where a hostname was removed from a data source after migrating to a new receiver. |
ELM Device | SIEM-33961 | Added validation to check that the ELM MGTDB storage location can handle files over 2GB in size. |
Policy, ASP Rule Editor | SIEM-37328 | An incorrect error message would be displayed when the policy editor was locked by another user. |
Policy Rollout | SIEM-27383 | Ending the value of an ASP variable with a '$' would cause policy rollout to fail. |
NGC Collector | SIEM-38149 | The NGC configuration parser will ignore unreadable data source configurations and log an appropriate message in the NGC logs. |
Receiver | SIEM-38125 | A red flag is no longer raised for a missing McAfeeP2P directory. |
AWS Platform | SIEM-38224 | Updated the AWS install scripts to allow for the latest kernels on EC2. |
Correlation, Historical Correlation | SIEM-38235 | Fixed a failure to trigger some correlation rules after receiving events with timestamps in the future. |
Collectors | SIEM-32160 | Resolved an NGC collection issue when no IP address was added to a data source. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.5.11.
Category | Reference | Resolution |
|---|---|---|
3rd party, Windows Rules | SIEM-37248 | Updated parsing rule 1011177 for the InterSect Alliance Snare for Windows data source to map additional data. |
3rd party, Dependent Device | SIEM-33762 | Updated the Trellix ePO – On prem query for ATP data to be more performant. |
Known issues
For a list of known issues in this product release, see KB90422.