The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.13 Release Notes

Prev Next

Trellix Enterprise Security Manager 11.6.13 addresses known issues.

This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.13

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade considerations

Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.

New or changed

  • You can integrate the following data sources with Trellix ESM:

    • ESET.

    • SentinelOne.

  • The Trellix ESM user interface has a new field called Match Missing Field. When this is selected, events without the specified field will also be considered for correlation.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

HA Receiver

SIEM-32238

Fixed an issue that caused HA failover events to time out early.

Software Upgrade

SIEM-33726

Updated Azul Java to address multiple CVEs.

Watchlists

SIEM-38940

Fixed an issue that caused string IDs, instead of string values, to be exported from watchlists.

Correlation

SIEM-39647

Fixed an issue that caused information to be excluded when the NOT IN correlation was used.

DSB Device

SIEM-39881

Fixed an issue that caused DSB Multi Node to fail.

User Interface

SIEM-40165

Fixed an issue that caused VM Disc space not to display.

Correlation

SIEM-40167

Fixed an issue that caused ISEF parsing and correlation grouping to fail after upgrading to Trellix ESM 11.6.10.

Software Upgrade

SIEM-40168

Updated the libcurl version to address CVE-2023-38545 and CVE-2023-38546.

HA Receiver

SIEM-40169

Fixed an issue that caused an error message that said HA device toggling had failed when it had been successful.

ELM Search

SIEM-40170

Fixed an issue that caused packet data retrieval to fail during Enterprise Log Manager (ELM) search.

Correlation

SIEM-40177

Fixed an issue that caused correlation diagnostics to not show the resources that top rules were consuming.

User Interface

SIEM-40184

Fixed an issue that caused the cursor to reset to its starting position when searching for a device.

User Interface

SIEM-40185

Fixed an issue that caused Trellix ESM interfaces to remain unchecked when accessed through the browser.

User Interface

SIEM-40186

Fixed an issue that caused the cursor to not automatically move to the selected data source after searching for a data source.

User Interface

SIEM-40207

Fixed an issue with the Trellix ESM user interface where multiple devices could not be selected for report filtering.

Correlation

SIEM-40211

Fixed an issue that caused a correlation instance map error.

User Interface

SIEM-40212

Fixed an issue on the policy rollout page that contained an invalid hyperlink.

Snow Service

SIEM-40252

Fixed an issue to address reverse shell vulnerability related to CVE-2024-11481 and CVE-2024-11482.

This release provides resolution for the following content issues through a rule update.

Category

Reference

Resolution

3rd party ASP rules

SIEM-40152

Updated parsing rules 1037448, 1046818, and 1048662 for  Database Security - CEF to fix an issue that prevented parsing of DAM logs.

3rd party ASP rules

SIEM-40166

Updated parsing rule 1051797 to fix an issue that prevented parsing of  IPS logs.

Known issues

For a list of known issues in this product release, see KB90422.