Trellix Enterprise Security Manager 11.6.8 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.8
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Cyberthreats | SIEM-39500 | Fixed an issue where the watchlist values were not updated based on the uploaded cyberthreat feeds. |
User Interface | SIEM-39502 | Fixed an issue that prevented the resizing of columns in ELM Data screen. |
ACE Device | SIEM-39548 | Fixed an issue that caused ACE health check to fail. |
Queries, Views | SIEM-28773 | Fixed an issue that displayed incorrect results on the dashboards while queries were run with custom fields. |
Correlation | SIEM-39496 | Fixed an issue that caused an unexpected symbol seen in the parameter name while editing a correlation rule. |
User Interface | SIEM-39222 | Fixed an issue that prevented some of the columns from being expandable on the Alarms tab. |
Middleware | SIEM-39590 | Fixed an issue that loaded the resources disproportionately causing ESM UI to slow down considerably. |
Content Packs, Queries, Views | SIEM-26425 | Fixed an issue that prevented one of the views from the Asset, threat, and risk content pack from loading on the UI. |
Software Upgrade | SIEM-33686 | Updated the file package to fix vulnerabilities in the earlier version. |
User Interface | SIEM-39577 | Fixed an issue that prevented the WMI logs from being displayed in the Select Event Logs Window. |
ELM Configuration | SIEM-37192 | Fixed an issue that prevented ELM logging configuration from persisting in rule correlation. |
User Interface | SIEM-39501 | Fixed an issue that caused dates to be incorrectly sorted on the ELM properties tab. |
User Interface | SIEM-39653 | Fixed an issue that prevented multiple device selection on the block list under the alarm settings. |
Correlation | SIEM-39538 | Fixed an issue that prevented the correlation rule from being triggered when correlation component was being used. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.7.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP | SIEM-39188 | Updated the parsing rule 1031927 for the TippingPoint data source. |
3rd party ASP | SIEM-39549 | Updated the parsing rule 1015829 for the Apache Web Server data source. |
Known issues
For a list of known issues in this product release, see KB90422.