The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading the Sensor from 10.1 or 11.1 to 11.1.5.72

Prev Next

If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.72, read the following sections carefully.

IPS support for multiple IVX brokers

Previously, IPS allowed users to integrate with a single IVX appliance broker node for malware analysis of files. Starting with this release of 11.1, IPS allows users to configure up to 5 IVX appliance broker nodes under the cluster. The Sensor submits files to the broker nodes in round robin manner for analysis and result polling, meaning better file submission rate and high availability are achieved.

Also, users can now configure broker nodes on IPv6 addresses unlike the earlier releases which supported only IPv4 communications.

In case of failed Manager-IVX or Sensor-IVX authentication, users can now view failure reason on the Manager UI which allows them to take corrective actions to attain successful authentication.

Note

At Device level, if you are inheriting admin domain configuration, make sure that both the Manager and the Sensor are running on software version 11.1 Update 4 or later. In case of heterogeneous scenarios where you are on a 11.1 Update 4 Manager and an older Sensor that supports only one broker node on IPv4, make sure you have added only one IPv4 broker address at Global level. If you have added an IPv6 address and the settings get inherited to the older Sensor, the file detection will not happen.

Note

It is highly recommended that you upgrade both the Manager and Sensor to 11.1 Update 4 or later releases to utilize multiple brokers which are connected over IPv4 and IPv6 addresses.

The following Sensor CLI commands are added:

Normal Mode

Command

Description

ivx lookup sha256

This command performs lookup on the entered SHA256 hash and returns details such as the verdict, report id, and the query time.

show ivxcloud config

This command displays the IVX Cloud configuration details.

show ivxcloud stats

This command displays statistics specific to IVX Cloud.

show ivxcloud status

This command displays the connection status of the IVX Cloud.



The following Sensor CLI commands are updated:

Normal Mode

Command

Description

show ivx config

This command now displays the configuration details of all the IVX broker nodes attached to the Sensor.

show ivx stats brokerid

This command now displays the statistics specific to the IVX broker nodes attached to the Sensor.

show ivx status brokerid

This command now displays the connection status of the IVX broker nodes attached to the Sensor.



The following Sensor CLI command is updated:

Debug Mode

Command

Description

show mgmtcfg

This command now displays the IVX broker node management configuration.



Device software deployment improvements in the Manager

In this release of 11.1, several enhancements have been made on the IPS Manager to improve and speed up the device software deployment operations. This is to cater to the bulk deployment requirements of network environments where large or very large number of Sensors are deployed. The Manager takes the following actions while handling bulk Sensor software upgrade requests:

  • The Manager reserves 100 GB under required free disk space for Manager operations and considers an additional file size of 1.2 GB to be generated for each software deployment request. When the Manager receives the software deployment requests in batches, it checks the number of Sensors selected, and calculates the free disk space required to complete the deployment operation. If there is insufficient disk space, an error message is displayed in the UI stating the available disk space and space required to complete the upgrade task. This enables the Manager to maintain optimal performance, secure sufficient disk space to keep other processes running, and avoid any software upgrade failure scenario.

  • Software deployments are critical operations and performed under approved/scheduled maintenance window. If the Manager receives multiple deployment requests in queue along with device software update requests, such as signature file and SSL keys deployments, it prioritizes the software deployment requests ahead of all other requests. It also performs disk usage optimization for each deployment to help you perform more deployments at a faster speed, and complete the critical task of software deployments within the approved/scheduled maintenance time.

Note

Very large Sensor deployments mean that the number of Sensors deployed is more than 100. Large Sensor deployments have Sensors numbering between 36 and 100+.

Support for external file reputation through Trellix Threat Intelligence Exchange (TIE)

Starting with this release of 11.1, IPS allows users to integrate an external file reputation provider to the existing list of TIE providers. This will allow the sensor to receive a reputation score for the file from the External Provider.

Cache implementation for Trellix Threat Intelligence Exchange (TIE) / Global Threat Intelligence (GTI) File Reputation

Starting with this release of 11.1, caching support is extended to Trellix TIE/GTI File Reputation service. Following Sensor CLI commands are updated for TIE/GTI cache implementation:

Normal Mode

Command

Description

clearmalwarecache

This command now allows users to clear cache entries related to TIE/GTI engine made in the Sensor.

malwarecache

This command now enables or disables malware cache for TIE/GTI engine



Debug Mode

Command

Description

show malwareserverstats

This command now includes an entry called Artemis Cache hit Cnt to display the number of times TIE/GTI cache is being read.



Rebranding updates

This is solely for informational purpose, there is no action required. You will notice the following changes:

  • Trellix Vector Execution is renamed to Trellix Intelligent Virtual Execution - Server (Trellix VX/ IVX) and Trellix Detection as a Service is renamed to Trellix Intelligent Virtual Execution Cloud (Trellix IVX Cloud/ IVX Cloud). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.

  • Trellix Investigation Analysis is renamed to Trellix Network Investigator (NI). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.

IPS CLI enhancements

The following Sensor CLI commands are updated:

Normal Mode

Command

Description

clearmalwarecache

This command has been updated with respect to the rebranding changes made on MVX. If users plan to delete cache entries of IVX, they need to issue the command clearmalwarecache ivx.

malwarecache

This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable or disable malware cache of IVX engine, they need to use the syntax malwarecache <enable | disable> ivx.



The following Sensor CLI commands are updated:

Debug Mode

Command

Description

set malwareEngine

This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable/disable the IVX malware engine for Advanced Malware inspection, they need to issue the syntax set malwareEngine ivx <enable | disable.

show ni status

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

getnistats

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

clearnistats

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

ninetflowstat

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.



Note

Apart from the above listed commands, a few more commands have been updated where the output displays the rebranding changes. As these changes do not have impact over the commands you input, they have not been listed here.