The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.2 Release Notes

Prev Next

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.2

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade Considerations

Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.

When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.

  1. Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.

  2. Skip step 6.

  3. On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.

Note

The above steps are only needed when upgrading to 11.6.x for the first time.

New features and changes

This release includes these changes.

Event forwarding:

Event forwarding is enhanced in this release to provide better usability and performance. Review all the Event Forwarder settings after the upgrade. Below are the important changes:

  • Legacy formats have been consolidated into CEF (Common Event Format) and SEF (Standard Event Format). All other formats will be converted to these two formats on upgrade.

  • Legacy Time format has been removed.

  • The 10-device filter limit for an Event Forwarder has been removed.

  • Each TESM appliance in a cluster will now forward directly to each forwarding destination. For SSH mode forwarders make sure the new Event Forwarding SSH key is added to each SSH destination. This new key is shared between all TESMs in the cluster.

  • Event forwarding configuration changes are propagated to non-management TESMs by the nsync process; changes will take effect when the next nsync thread completes.

Enhanced the UBA content pack(v4.2.0) by adding the following rules:

  • UBA - Multiple User Accounts Created

  • UBA - User Account Created and Deleted Within a Short Time

  • Hardware Health - Increase in Hardware Errors for Host

  • UBA - Increase in unique hosts a system is communicating

  • UBA - Increase in unique hosts a user is logging into

  • UBA - Increase in Failures on Single Host

Removed features

This release removes support for this feature.

Security Weighting — The Security Weighting feature helped with the ability to adjust and calculate the severity of assets, tags, rules, and vulnerabilities. We have removed this ability to configure severity from ESM and moved the customization of rule severity alone to the ACE framework with this release.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

User Interface

SIEM-38530

Resolved an error when creating a static watchlist with more than one entry.

ACE Device

SIEM-38469

Resolved an issue that caused the ACE health check to return an ER234 error: Unable to execute a command on the device.

ESM Device

SIEM-38444

Added Deviation from Baseline and Specified Event Rate alarms to be checked by the System Properties > Watchlists > Show Usage feature.

Certificates, User Interface

SIEM-38401

Resolved an (ER354) error: Could not execute SSH command when generating a Signed Certificate Request.

User Interface

SIEM-37057

Resolved an issue that caused the Streaming Event Viewer to not show events.

Security

SIEM-35241

Updated Tomcat and associated libraries to resolve CVE-2022-25762.

User Interface

SIEM-38623

Resolves an issue that caused the Trellix Threat Intelligence Exchange execution history UI to not load.

Alarms

SIEM-38422

Resolved an issue that would cause real time alarms not to trigger when the event queue was full.

This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.1.

Category

Reference

Resolution

3rd party

SIEM-38497

Fixed an issue which caused the TIE Content Pack to fail to install on versions 11.6.0 and greater.

3rd party ASP

SIEM-38445

Resolved an issue that prevented parsing of Skyhigh CASB logs.

Known issues

For a list of known issues in this product release, see KB90422.