Configure and install the Historical Search module on the Endpoint Security (HX) On-prem server before you connect the server to the EDR Telemetry Store.
Install the Historical Search module
Prerequisite:
The Historical Search module requires a .cms file for installation on the Endpoint Security (HX) console. You must download this file before you begin the installation process. For details, see Download methods.
This file is part of the EDRF On-prem add-on package, as detailed in the System Requirements.
Download methods
Use one of these methods to obtain the .cms file:
Software Catalog
Trellix Downloads site
Software Catalog
Log in to ePO - On-prem.
Navigate to Menu → Software → Software Catalog and select Threat Analysis.
Select Trellix EDR with Forensics On-Prem - Add-On 25.11 or later, and download the Historical Search module for HX.
The
.cmsfile downloads to your local file system.Upload the downloaded package in the Endpoint Security (HX) console as mentioned in Install the Historical Search module section.
Trellix Downloads site
Access the Trellix Downloads site using the URL https://www.trellix.com/downloads/my-products/.
Log in using your Grant Number and registered Email Address.
In the Find Products page, under the Filters category, select Threat Analysis.
Select Trellix EDR with Forensics On-Prem - Add-On 25.11 or later, and download the Historical Search module for HX.
The
.cmsfile downloads to your local file system.Upload the downloaded package in the Endpoint Security (HX) console as mentioned in Install the Historical Search module section.
Install the Historical Search module
Log in to the Endpoint Security (HX) console as an administrator.
Navigate to Menu → Endpoint Module Administration.
Click Install Modules and then click Select File.
Select the
.cmsfile downloaded to your local file system and click Upload.The module is now added to the Installed Modules list.
Enable the Historical Search module
On successful installation of the Historical Search module, you must enable and configure the module.
In the Installed Modules list, locate the Historical Search module.
Click the gear icon for that module and click Enable.
In the confirmation dialog that appears, click Enable.
Note
Policies for streaming trace data are configured from the EDRF Streaming policy in Trellix ePO.