Install and enable the Historical Search module on Endpoint Security (HX)

Prev Next

Configure and install the Historical Search module on the Endpoint Security (HX) On-prem server before you connect the server to the EDR Telemetry Store.

Install the Historical Search module

Prerequisite:

The Historical Search module requires a .cms file for installation on the Endpoint Security (HX) console. You must download this file before you begin the installation process. For details, see Download methods.

This file is part of the EDRF On-prem add-on package, as detailed in the System Requirements.

Download methods

Use one of these methods to obtain the .cms file:

  • Software Catalog

  • Trellix Downloads site

Software Catalog
  1. Log in to ePO - On-prem.

  2. Navigate to MenuSoftwareSoftware Catalog and select Threat Analysis.

  3. Select Trellix EDR with Forensics On-Prem - Add-On 25.11 or later, and download the Historical Search module for HX.

    The .cms file downloads to your local file system.

  4. Upload the downloaded package in the Endpoint Security (HX) console as mentioned in Install the Historical Search module section.

Trellix Downloads site
  1. Access the Trellix Downloads site using the URL https://www.trellix.com/downloads/my-products/.

  2. Log in using your Grant Number and registered Email Address.

  3. In the Find Products page, under the Filters category, select Threat Analysis.

  4. Select Trellix EDR with Forensics On-Prem - Add-On 25.11 or later, and download the Historical Search module for HX.

    The .cms file downloads to your local file system.

  5. Upload the downloaded package in the Endpoint Security (HX) console as mentioned in Install the Historical Search module section.

Install the Historical Search module
  1. Log in to the Endpoint Security (HX) console as an administrator.

  2. Navigate to MenuEndpoint Module Administration.

  3. Click Install Modules and then click Select File.

  4. Select the .cms file downloaded to your local file system and click Upload.

    The module is now added to the Installed Modules list.

Enable the Historical Search module

On successful installation of the Historical Search module, you must enable and configure the module.

  1. In the Installed Modules list, locate the Historical Search module.

  2. Click the gear icon for that module and click Enable.

  3. In the confirmation dialog that appears, click Enable.

    Note

    Policies for streaming trace data are configured from the EDRF Streaming policy in Trellix ePO.