Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.2
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
New features and changes
This release includes these changes.
Event forwarding:
Event forwarding is enhanced in this release to provide better usability and performance. Review all the Event Forwarder settings after the upgrade. Below are the important changes:
Legacy formats have been consolidated into CEF (Common Event Format) and SEF (Standard Event Format). All other formats will be converted to these two formats on upgrade.
Legacy Time format has been removed.
The 10-device filter limit for an Event Forwarder has been removed.
Each TESM appliance in a cluster will now forward directly to each forwarding destination. For SSH mode forwarders make sure the new Event Forwarding SSH key is added to each SSH destination. This new key is shared between all TESMs in the cluster.
Event forwarding configuration changes are propagated to non-management TESMs by the nsync process; changes will take effect when the next nsync thread completes.
Enhanced the UBA content pack(v4.2.0) by adding the following rules:
UBA - Multiple User Accounts Created
UBA - User Account Created and Deleted Within a Short Time
Hardware Health - Increase in Hardware Errors for Host
UBA - Increase in unique hosts a system is communicating
UBA - Increase in unique hosts a user is logging into
UBA - Increase in Failures on Single Host
Removed features
This release removes support for this feature.
Security Weighting — The Security Weighting feature helped with the ability to adjust and calculate the severity of assets, tags, rules, and vulnerabilities. We have removed this ability to configure severity from ESM and moved the customization of rule severity alone to the ACE framework with this release.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
User Interface | SIEM-38530 | Resolved an error when creating a static watchlist with more than one entry. |
ACE Device | SIEM-38469 | Resolved an issue that caused the ACE health check to return an ER234 error: Unable to execute a command on the device. |
ESM Device | SIEM-38444 | Added Deviation from Baseline and Specified Event Rate alarms to be checked by the System Properties > Watchlists > Show Usage feature. |
Certificates, User Interface | SIEM-38401 | Resolved an (ER354) error: Could not execute SSH command when generating a Signed Certificate Request. |
User Interface | SIEM-37057 | Resolved an issue that caused the Streaming Event Viewer to not show events. |
Security | SIEM-35241 | Updated Tomcat and associated libraries to resolve CVE-2022-25762. |
User Interface | SIEM-38623 | Resolves an issue that caused the Trellix Threat Intelligence Exchange execution history UI to not load. |
Alarms | SIEM-38422 | Resolved an issue that would cause real time alarms not to trigger when the event queue was full. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.1.
Category | Reference | Resolution |
|---|---|---|
3rd party | SIEM-38497 | Fixed an issue which caused the TIE Content Pack to fail to install on versions 11.6.0 and greater. |
3rd party ASP | SIEM-38445 | Resolved an issue that prevented parsing of Skyhigh CASB logs. |
Known issues
For a list of known issues in this product release, see KB90422.