Trellix EDR with Forensics (EDRF) On-prem March 2026 release includes the defect fixes, with user experience improvements in the EDR Telemetry Store and Historical Search module.
Release details
This release includes the following components:
Component | Version | Description |
|---|---|---|
EDR Telemetry Store virtual appliance | 26.03.0.16 | OVA package for new installations. |
EDR Telemetry Store Upgrade package | 26.03.0.16 | Upgrade package required for existing environments on version 25.11. |
Historical Search module | 1.1.0 | .cms file for HX Server. Required for both new and existing installations. |
For release details and supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
UI improvements
Custom time range selection in the Historical Search UI
The Historical Search UI now displays the specific date and time interval selected in the Time Range instead of a generic Custom label. The selected timestamp is shown in the following format:
From: DD/MM/YYYY HH:MM:SS (UTC) To: DD/MM/YYYY HH:MM:SS (UTC)
Error message handling in the Historical Search UI
The Historical Search UI now displays a single error message for invalid queries instead of multiple error messages. The error message is automatically dismissed when the search query is valid.
Host Details navigation from Historical Search UI
The Event Details side panel now includes a View Host Details link. Click this link to open the All Hosts page in the Endpoint Security (HX) console in a new tab. To view specific device details, click the plus symbol next to the host. This displays the IP address, Agent ID, OS version, and network adapter information.
For more information, see All Hosts page.
Network DNS name display in the Historical Search UI
The Network DNS name column in the Historical Search UI now displays as a comma-separated string for Network Accessed event types instead of a nested JSON array. When you add this column to a query, the Network DNS name column now populates with readable values and maintains the same format in CSV exports.
This feature requires EDRF Client version 50.2.x or later.
For more information, see Network DNS name representation in the Historical Search UI.
Certificate support for EDR Telemetry Store
Support for Trellix ePO custom certificates
The EDR Telemetry Store now automatically collects and updates the ePolicy Orchestrator (ePO) root certificate to support environments using custom certificates for the ePO console. Previously, a manual workaround was required to establish a trusted mTLS connection between the DXL Broker and the EDR Telemetry Store. The system now retrieves the ePO root certificate through a remote command to ensure the EDR Telemetry Store maintains a trusted connection and facilitates the trace data flow.
Support for 3K CA-signed certificates
The EDR Telemetry Store now supports the migration of ePO root certificates from 2K to 3K CA-signed certificates. This update ensures a trusted mTLS connection between the DXL Broker and the EDR Telemetry Store. You can perform this update through the Certificate Configuration options within the EDR Telemetry Store cluster setup wizard.
For more information about ePO certificate updates, see Update ePO certificates.
Individual JVM memory allocation for a multi-node cluster
For a multi-node cluster, the Cluster Setup Wizard now prompts for JVM memory values for each node role individually. You can assign a separate memory value for the cluster manager, ingest, and the data node during the initial cluster configuration or when you edit the cluster.
For more information, see Configure the node.
Known Issues
For a list of known issues in this product release, see the Trellix Knowledge Base article, Trellix EDR with Forensics Known Issues - KB000015039.