EDRF On-prem deployment models

Prev Next

EDRF On-prem is designed for users with 2,000 or more endpoints. Select the model that fits your infrastructure capabilities.

  • Minimum deployment (2000+ endpoints)

    Requires 3 total servers to be functional.

    • 1 Endpoint Security (HX) server

    • 1 ePO - On-prem server (Agent Handler, SQL, and DXL Broker)

    • 1 EDR Telemetry Store virtual appliance

    This configuration generates approximately 90–100 GB of data daily. Consequently, a 12 TB OpenSearch storage volume provides more than 120 days of retention. Each 1 TB of data storage provides approximately 10 days of retention.

  • Medium deployment ( >50000 endpoints)

    Requires a minimum of 9 to 15 servers. Services must be separated onto dedicated servers to ensure performance.

    • 1 ePO - On-prem server

    • 1 ePO - On-prem server

    • 3–5 EDR Telemetry Store virtual appliances

    • 1 SQL Server

    • 3 DXL Brokers

    • 2 Trellix TIE Servers (optional)

    • 2 Agent Handlers (optional)

    A deployment of 50,000 endpoints generates approximately 2.4 TB of data daily. Using two data nodes, each with 12 TB of storage, provides more than 10 days of retention.

  • Large deployment ( > 100000 endpoints)

    For deployments with more than 100,000 endpoints, contact Trellix Support or Trellix Professional Services.

Deployment best practices

Follow these guidelines to ensure optimal performance and stability for your deployment.

  • Storage type: Use solid-state drive (SSD) or Non-Volatile Memory Express (NVMe) storage for EDR Telemetry Store nodes.

  • Node count: Deploy a minimum of three nodes for environments exceeding 5,000 endpoints.

  • Time synchronization: Maintain strict Network Time Protocol (NTP) synchronization across all appliances and servers.

  • Replication: Set the replication factor to 1 to maximize retention. Increase this value only if your environment requires high availability for indexed data.