Trellix Enterprise Security Manager 11.7.3 contains feature enhancements and addresses known issues.
Release details of Trellix ESM 11.7.3
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.7.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.7.x version for the first time.
New or changed
LDAPS support for watchlists and data enrichment
You can use LDAPS (LDAP over TLS) to configure directory sources. This protects authentication credentials and sensitive user data. In the Data Enrichment Wizard, select Use TLS to securely connect to the LDAP server.
Active flags identifies specific receiver node
When an active flag is generated for a data source in a high availability receiver pair, the device name shows which receiver the data source belongs to.
Synchronize event data in clustered ESM nodes
To ensure there is no difference in widget event data between clustered ESM nodes and their corresponding replicas, the Enable ESM Replica Sync check box has been added to the System Properties > Clustering page. For more information, see Enabling ESM replica synchronization.
Hostname column added to Device Summary reports
The Host Name column has been added to the Device Summary Report. Where available, the hostname will appear in the report, otherwise the field will be blank.
Partition failure alerts
A warning is displayed in the physical device display status alert list if a data partition transitions to a detached or marked bad state.
Improved error handling
More context has been added to the error message Correlation Packet Length Exceeded (ER279) to explain that the correlation rule exceeds the maximum packet size of 32 KB.
Log files with multiple extensions
The getstatsdata script now collects log files with multiple extensions.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Collectors | SIEM-40940 | Fixed an issue that caused NPP_c not to start after the receiver was restarted. |
Collectors | SIEM-40946 | Fixed an issue with the automatic recovery of syslogcollector. The collector now restarts automatically if it crashes. |
Security | SIEM-40919 | Fixed an issue that caused the specific Apache version number to be exposed in the server HTTP response. |
Security | SIEM-40930 | Fixed an issue that required additional validation of the Cross-Site Request Forgery (CSRF) token |
User Interface | SIEM-40941 | Fixed an issue that caused an error editing existing WMI datasources. |
User Interface | SIEM-41019 | Fixed an issue that caused an issue loading the System properties > Event workflows views > Triggered alarms page in the UI. |
User Interface | SIEM-41043 | Fixed an issue that caused an error message when configuring data enrichment. |
User Interface | SIEM-41046 | Fixed an issue that caused the wrong error message to display when running a test connection for AD and LDAP servers on the data enrichment page. |
Watchlists | SIEM-40949 | Fixed an issue that caused a validation error when creating http/https watchlists. |
This release provides resolution for the following content issues through a rule update.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP rules | SIEM-40694 | Fixed an issue with correctly parsing Hebrew characters. |
Known issues
For a list of known issues in this product release, see KB90422.