Trellix Enterprise Security Manager 11.6.6 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.6
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
ELM Device | SIEM-19483 | Resolved an issue that prevented ELM pools from being deleted when not assigned to a data source. |
Internal Events | SIEM-38644 | Fixed an issue to enable ESM to populate internal events with proper source and destination IPs. |
NPP Collector | SIEM-39211 | Fixed an issue that prevented the NPP collector from collecting SQL c2 audit logs via the SIEM collector. |
User Interface | SIEM-28572 | Fixed an issue that was preventing case management views to load completely when there was % in a custom type field. |
User Interface | SIEM-33083 | Fixed an issue to show the variables tab for custom type strings in the correlation filter. |
User Interface | SIEM-31987 | Source events within a correlation event are now shown in the user's time zone. |
ESM Device | SIEM-39303 | Resolved an issue that prevented an http/https dynamic watch list from being created. |
Software Upgrade | SIEM-37020 | Updated the TCPDump library to version 4.99.4. |
Software Upgrade | SIEM-33725 | Updated the wget package to version 1.21. |
Software Upgrade | SIEM-33724 | Upgraded the patch package to 2.7.6. |
User Interface | SIEM-39322 | Resolved an issue where the Text to fields are not aligned properly. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.5.
Category | Reference | Resolution |
|---|---|---|
3rd party | SIEM-39294 | The name of parsing rule 1051797 was updated to Trellix - IPS Manager data source. |
3rd party ASP | SIEM-38190 | Updated the parsing rules the BlueCoat Reporter data source. |
3rd party ASP | SIEM-39069 | Parsing rules 1070845 through 1070848 were added to the Windows DNS data source. |
3rd party ASP | SIEM-39160 | Updated parsing rule 1011177 for the InterSect Alliance Snare for Windows data source. |
3rd party | SIEM-39150 | Fixed issue preventing event collection for the ePO Saas data source. |
3rd party ASP | SIEM-38221 | Updated parsing rule 1070712 for the Microsoft Advanced Threat Protection (ATP) data source. |
3rd party ASP | SIEM-38446 | Parsing rules 1046567 through 1046603 were updated and 1070820 through 1070844 were added to the OpenVPN data source. |
Known issues
For a list of known issues in this product release, see KB90422.