Migrate from Active Response to Trellix EDR

Prev Next

If you are using Trellix® Active Response 2.3 or later, you can migrate to Trellix EDR.

Note

When you migrate from a localized version of Active Response software to Trellix EDR, it migrates only to an English-only system.

Once the devices using Active Response are successfully migrated, the potential threats start appearing on the Monitoring dashboard in Trellix EDR. All traces and events from Active Response go to the Trellix EDR Cloud. The Active Response workspace is not updated anymore and can be used only to view previous activity. No further actions are triggered from this workspace.

The Trellix EDR Monitoring dashboard shows data from the Trellix EDR clients which collects all the system information details during each trace. When migrating endpoints from Active Response to Trellix EDR, once you update the ePO - SaaS Cloud Bridge page with the Trellix EDR email ID, the DXL broker starts sending Active Response trace data into the Trellix EDR Monitoring dashboard instead of the Active Response Workspace page. However, you might see the trace data from Active Response clients does not populate the Host name information. For details, see KB95291.

If you can’t migrate all Active Response clients installed on endpoints at a time, and want to investigate data from these Active Response clients within the Trellix EDR Monitoring dashboard, see the solution mentioned in KB95291.

Note

Upon installation or upgrade of the Trellix EDR client, you might have to reboot the client system.

Some Active Response features like saved searches or triggers are not supported by Trellix EDR. But existing triggers or saved searches remain available and usable on Active Response 2.x.

Important

When you migrate to Trellix EDR, you can remove all Active Response extensions except the mar-client extension. This is required to monitor the devices that are not migrated to Trellix EDR.