Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.5
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
New features and changes
This release includes these changes.
Trellix ESM now supports a new generation of hardware appliance - ESM generation 6. You can upgrade to Trellix ESM generation 6 appliance hardware to benefit from the latest software developments.
FSO integration with ESM – Enables SOAR capabilities for ESM users with TSO licenses.
ELM Query performance improvements.
Additional Royale UI fixes.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Clustering, Middleware | SIEM-37183 | Resolved an issue where passwords for non-management ESM nodes were stored in plain text format in the database. |
Correlation | SIEM-39146 | Resolved an issue where the ACE was triggering incorrectly on logical Severity comparisons. |
Data Source | SIEM-38629 | Resolved an issue that caused the UI to freeze and user logins to fail. |
ELM Device | SIEM-28870 | Fixed an issue where after performing a format on iSCSI, the UI would indicate that a format was required. |
ELM Device | SIEM-38555 | Resolved an issue that caused rsync_copy to not complete. |
ELM Device | SIEM-33588 | Resolved an issue where ELM status was Not OK - elmcompressctl not running. |
Installation | SIEM-38804 | Resolved an issue where the AWS install script failed to install. |
Logs | SIEM-38636 | Resolved an issue where compressed messages files from a device data export were corrupted. |
Watchlists | SIEM-38988 | Resolved an issue where ACE rules triggered incorrectly when it was using a NOT logic operator against a Watchlist. |
ACE Device | SIEM-39017 | Resolved an issue where a correlation data source stopped working on an ENMELM. |
ACE Device | SIEM-39204 | Resolved an issue with the ACE state database configuration during the upgrade process. |
Known issues
For a list of known issues in this product release, see KB90422.