EDRF On-prem March 2026

Prev Next

Trellix EDR with Forensics (EDRF) On-prem March 2026 release includes the defect fixes, with user experience improvements in the EDR Telemetry Store and Historical Search module.

Release details

This release includes the following components:

Component

Version

Description

EDR Telemetry Store virtual appliance

26.03.0.16

OVA package for new installations.

EDR Telemetry Store Upgrade package

26.03.0.16

Upgrade package required for existing environments on version 25.11.

Historical Search module

1.1.0

.cms file for HX Server. Required for both new and existing installations.

For release details and supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

New or changed

UI improvements
  • Custom time range selection in the Historical Search UI

    The Historical Search UI now displays the specific date and time interval selected in the Time Range instead of a generic Custom label. The selected timestamp is shown in the following format:

    From: DD/MM/YYYY HH:MM:SS (UTC) To: DD/MM/YYYY HH:MM:SS (UTC)

  • Error message handling in the Historical Search UI

    The Historical Search UI now displays a single error message for invalid queries instead of multiple error messages. The error message is automatically dismissed when the search query is valid.

  • Host Details navigation from Historical Search UI

    The Event Details side panel now includes a View Host Details link. Click this link to open the All Hosts page in the Endpoint Security (HX) console in a new tab. To view specific device details, click the plus symbol next to the host. This displays the IP address, Agent ID, OS version, and network adapter information.

    For more information, see All Hosts page.

  • Network DNS name display in the Historical Search UI

    The Network DNS name column in the Historical Search UI now displays as a comma-separated string for Network Accessed event types instead of a nested JSON array. When you add this column to a query, the Network DNS name column now populates with readable values and maintains the same format in CSV exports.

    This feature requires EDRF Client version 50.2.x or later.

    For more information, see Network DNS name representation in the Historical Search UI.

Certificate support for EDR Telemetry Store
  • Support for Trellix ePO custom certificates

    The EDR Telemetry Store now automatically collects and updates the ePolicy Orchestrator (ePO) root certificate to support environments using custom certificates for the ePO console. Previously, a manual workaround was required to establish a trusted mTLS connection between the DXL Broker and the EDR Telemetry Store. The system now retrieves the ePO root certificate through a remote command to ensure the EDR Telemetry Store maintains a trusted connection and facilitates the trace data flow.

  • Support for 3K CA-signed certificates

    The EDR Telemetry Store now supports the migration of ePO root certificates from 2K to 3K CA-signed certificates. This update ensures a trusted mTLS connection between the DXL Broker and the EDR Telemetry Store. You can perform this update through the Certificate Configuration options within the EDR Telemetry Store cluster setup wizard.

For more information about ePO certificate updates, see Update ePO certificates.

Individual JVM memory allocation for a multi-node cluster

For a multi-node cluster, the Cluster Setup Wizard now prompts for JVM memory values for each node role individually. You can assign a separate memory value for the cluster manager, ingest, and the data node during the initial cluster configuration or when you edit the cluster.

For more information, see Configure the node.

Known Issues

For a list of known issues in this product release, see the Trellix Knowledge Base article, Trellix EDR with Forensics Known Issues - KB000015039.