The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.14 Release Notes

Prev Next

Trellix Enterprise Security Manager 11.6.14 addresses known issues.

This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.14

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade considerations

Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.

New or changed

  • You can now apply a filter before you export device summary reports. On the View Reports page, a new tab called Device Status lists all datasources and their status. Select the checkbox to include all datasources, only those that are enabled, or only those that are disabled when you export the device summary report.

  • You can now save ELM backup files in the ELM device itself.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

Datasources

SIEM-26751

Fixed an issue when exporting data sources that caused the fields enabled and parsing to be excluded.

ESM device

SIEM-37052

Fixed an issue that caused sub-menus not to display when you hovered over them.

ERC device

SIEM-39664

Fixed an issue retrieving a vulnerability report on a connected Nexpose Rapid7 VA.

Correlation

SIEM-39795

Fixed an issue that caused rules to break when using the dollar sign ($) in regular expressions.

User interface

SIEM-39887

Fixed an issue with port allocation that caused excessive errors on the Trellix ESM device log.

Alarms

SIEM-40019

Fixed an issue that caused acknowledged alarms to display the incorrect date format.

API

SIEM-40096

Fixed an issue that caused the zoneGetSubZone API to return empty fields.

User interface

SIEM-40156

Fixed an issue that caused reports using a bar chart and saved in HTML format not to be generated.

User Interface

SIEM-40186

Fixed an issue that caused the cursor to not automatically move to the selected data source after searching for a data source.

User interface

SIEM-40216

Fixed an issue that caused the Device Summary Reports event time field to take an excessive time to populate when using a web browser.

User interface

SIEM-40225

Fixed an issue that caused you to be unable to set the color of the boarder or font in reports.

Software upgrade

SIEM-40259

Updated javascript and tomcat to address CVE-2018-20801, CVE-2019-10744, CVE-2022-25844, and CVE-2023-46589.

ERC device

SIEM-40273, SIEM -40285

Fixed an issue that caused healthmon not to get the status of kafka.

ELM device

SIEM-40279

Fixed an issue that caused the Storage Pool page to be unresponsive when accessed using a web browser.

ESM device

SIEM-40280, SIEM-40293

Fixed an issue that caused CRL validation to fail when a new certificate file was uploaded to Trellix ESM if there was an existing certificate.

HA receiver

SIEM-40312

Fixed an issue that caused logs collected and parsed on Cisco Firepower Management Center - eStreamer to display the incorrect first time and last time.

Correlation

SIEM-40314

Fixed an issue that caused no correlated events to appear in the dashboard after updating from 11.6.9 to 11.6.13.

Policy rollout

SIEM-40328

Fixed an issue that caused inconsistent errors when manually rolling out policies to all devices after updating from 11.6.12 to 11.6.13.

Middleware

SIEM-40368

Fixed an issue that caused the NGCP password change script to fail to update the password when executed through cronjob.

Correlation

SIEM-40369

Fixed an issue with errors seen in correlation logs when alarms were triggered inconsistently.

This release provides resolution for the following content issues through a rule update.

Category

Reference

Resolution

3rd party ASP rules

SIEM-40260

Rule 43-471020970 has been added to parse the following Windows Defender Firewall fields: ModifyingApplication, ModifyingUser, RuleName, Direction,Protocol, LocalPorts, and Action.

3rd party ASP rules

SIEM-40276

Updated parsing rules 1068944 to 1068979 to fix an issue that prevented parsing of Skyhigh Secure Webgateway logs.

3rd party ASP rules

SIEM-40329

Due to issues parsing Trellix IPS logs, the log format has been changed.

Known issues

For a list of known issues in this product release, see KB90422.