Trellix continuously updates policy, parser, and rule updates used to examine network traffic. You can download rule updates automatically or manually from the Trellix server.
Within 30 days of access, request permanent credentials for rule updates.
To request credentials, email your grant ID, account name, and contact information to Licensing@Trellix.com.
Validate your permanent credentials.
From the dashboard, click
then select Click Credentials, then type the customer ID and password.
Click Validate.
Enable Automatic Geolocation Updates post upgrade to 11.5.1 (Optional and enable this if you utilize geolocation in the SIEM):
SSH to Trellix ESM.
Run the following command [
nquery -d esm -q "update syssettings set value='False' where attribute='GeoLocRuleUpdateDisabled'"].Validate the settings that are applied.
Run the following command [
nquery -d esm -q "select * from syssettings where attribute='GeoLocRuleUpdateDisabled'"].Validate the output as False.
Note
Geolocation update files are around 4 GB size. Make sure this feature if you are OK with a regular (weekly) update size.
Check for rule updates:
Auto check interval to set up the system to check for updates automatically with the frequency you select.
Check Now to check for updates now.
Manual Update to update the rules from a local file.