The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.7.3 Release Notes

Prev Next

Trellix Enterprise Security Manager 11.7.3 contains feature enhancements and addresses known issues.

Release details of Trellix ESM 11.7.3

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade considerations

Trellix ESM 11.7.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.7.x version for the first time.

New or changed

LDAPS support for watchlists and data enrichment

You can use LDAPS (LDAP over TLS) to configure directory sources. This protects authentication credentials and sensitive user data. In the Data Enrichment Wizard, select Use TLS to securely connect to the LDAP server.

Active flags identifies specific receiver node

When an active flag is generated for a data source in a high availability receiver pair, the device name shows which receiver the data source belongs to.

Synchronize event data in clustered ESM nodes

To ensure there is no difference in widget event data between clustered ESM nodes and their corresponding replicas, the Enable ESM Replica Sync check box has been added to the System Properties > Clustering page. For more information, see Enabling ESM replica synchronization.

Hostname column added to Device Summary reports

The Host Name column has been added to the Device Summary Report. Where available, the hostname will appear in the report, otherwise the field will be blank.

Partition failure alerts

A warning is displayed in the physical device display status alert list if a data partition transitions to a detached or marked bad state.

Improved error handling

More context has been added to the error message Correlation Packet Length Exceeded (ER279) to explain that the correlation rule exceeds the maximum packet size of 32 KB.

Log files with multiple extensions

The getstatsdata script now collects log files with multiple extensions.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

Collectors

SIEM-40940

Fixed an issue that caused NPP_c not to start after the receiver was restarted.

Collectors

SIEM-40946

Fixed an issue with the automatic recovery of syslogcollector. The collector now restarts automatically if it crashes.

Security

SIEM-40919

Fixed an issue that caused the specific Apache version number to be exposed in the server HTTP response.

Security

SIEM-40930

Fixed an issue that required additional validation of the Cross-Site Request Forgery (CSRF) token

User Interface

SIEM-40941

Fixed an issue that caused an error editing existing WMI datasources.

User Interface

SIEM-41019

Fixed an issue that caused an issue loading the System properties > Event workflows views > Triggered alarms page in the UI.

User Interface

SIEM-41043

Fixed an issue that caused an error message when configuring data enrichment.

User Interface

SIEM-41046

Fixed an issue that caused the wrong error message to display when running a test connection for AD and LDAP servers on the data enrichment page.

Watchlists

SIEM-40949

Fixed an issue that caused a validation error when creating http/https watchlists.

This release provides resolution for the following content issues through a rule update.

Category

Reference

Resolution

3rd party ASP rules

SIEM-40694

Fixed an issue with correctly parsing Hebrew characters.

Known issues

For a list of known issues in this product release, see KB90422.