Trellix Enterprise Security Manager 11.6.15 contains feature enhancements and addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.15
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.
New or changed
The number of allowed static routes has been increased from 10 to 30 for ESM and ERC interfaces.
You can now configure which receiver the ELM internal events will be sent to.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
ACE device Middleware | SIEM-39784 | Fixed an issue that caused a rule to misfire when multiple values in the NOT_REGEX condition were used. |
Correlation | SIEM-40281 | Fixed an issue with missing characters in dynamic watchlists. |
Correlation | SIEM-40318 | Fixed an issue that caused a null pointer exception when a rule used a regular expression capture group. |
ESM device | SIEM-40307 | Fixed an issue that caused incorrect IP address to be returned when the HOME_NET variable was used. |
Hardware | SIEM-40324 | Fixed an issue with the healthmon script to report Gen6 hardware failure in the Web UI and logs. |
Policy roller | SIEM-39465 | Fixed an issue that prevented policies being rolled out. |
Streaming event streamer | SIEM-39315 | Fixed an issue that caused the Streaming view Web UI page to be blank. |
User interface | SIEM-40432 | Fixed an issue that caused the policy rollout to no work for Windows datasources. |
Known issues
For a list of known issues in this product release, see KB90422.