To install Trellix EDR, make sure your Trellix account is set up and activated.
Before deploying the Trellix EDR client on Linux endpoints, make sure to enable kernel syscall auditing to discover security violations and track security-relevant information. For details about enabling syscall auditing on different Linux distributions, see:
Note
After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.
Upon installation or upgrade of the Trellix EDR client, you might have to reboot the client system.
Log on to Trellix EDR as administrator.
Click the configuration icon on the top-right corner to access the Configuration page.
On the Configuration page, select Use Trellix ePO - SaaS for management.
Important
Make sure you select the correct configuration. This setting can only be changed with the assistance of Customer Support.
Click Save, then click Continue to confirm the configuration.
In the View account settings section, you can opt to share telemetry data by selecting I choose to share telemetry data (defined below) with Trellix and its third-party processors., then click Save.
Deploy the Trellix EDR client to devices:
Log on to ePO - SaaS as administrator.
Select Menu → Software → Product Deployment.
Select Advanced Options → Advanced Product Deployment, then click New Deployment.
Enter a name and description for the deployment task.
Select the appropriate Trellix EDR client package for Windows, Linux, or macOS endpoints as the software package.
Select Individual Systems or by Tag or Group to open the System Selection window.
From System Tree, on the System Selection page, select the devices where you want to deploy the client software, then click OK.
Choose Run Immediately to start the deployment task immediately.
Click Save.
Note
When installing Trellix EDR client on macOS endpoints, the endpoint user is prompted with pop-ups to grant permission for TrellixSystemExtensions on the general tab from the security and privacy page. Also, you must allow full disk access for TrellixSystemExtensions and fmpd on the privacy tab.
On Trellix EDR, go to the Configuration page and verify whether the connection status is green to confirm the deployment is complete, then click Done.