Trellix Enterprise Security Manager 11.7.2 contains feature enhancements and addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.7.2
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.7.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.7.x version for the first time.
New or changed
Trellix ESM supports Google Cloud Platform as an integrated data source.
The Geolocation file format has been changed to .xz for faster file downloads. For Trellix ESM versions earlier than 11.7.2, follow this KB article to continue deploying Geolocation updates.
The JSON Web Tokens used in Trellix ESM have been updated to conceal username information.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
API | SIEM-40621 | Fixed an issue that caused the API call notifyGetTriggeredNotificationDetail to return a null value for the AcknowledgedUser field. |
ESM device | SIEM-40385 | Fixed an issue that caused the ACE health script to incorrectly record a lag. |
User Interface | SIEM-40720 | Fixed an issue that caused UI elements to incorrectly display when you edited an existing field match alarm. |
WMI | SIEM-40723 | Fixed an issue that prevented the WMI process restarting. |
Known issues
For a list of known issues in this product release, see KB90422.