To successfully replace an integrated Central Management System appliance or Endpoint Security (HX) server, you must manually configure the Endpoint Security (HX) server Bookmark ID. This manual configuration ensures retrieval of relevant IOCs in a timely manner from the Central Management System appliance.
Overview
When an Endpoint Security (HX) server is managed by a Central Management System appliance, the Central Management System appliance sends a notification of the latest Alert ID to the Endpoint Security (HX) server. The Endpoint Security (HX) server then polls the Central Management System appliance for the Alert ID and retrieves Indicators Of Compromise (IOC) details for the specified alert. The Endpoint Security (HX) server then updates the Bookmark ID to identify the next Alert ID to use when polling the Central Management System appliance.
A newly manufactured Endpoint Security (HX) server has a Bookmark ID equal to zero. When the Endpoint Security (HX) server is attached to the Central Management System appliance, the Central Management System appliance will send the latest Alert ID to the Endpoint Security (HX) server. The Endpoint Security (HX) server will then poll the Central Management System appliance for all the Alert IDs from zero through to the latest Alert ID. The delta between the Endpoint Security (HX) server Bookmark ID and the Central Management System appliance latest Alert ID can be in the thousands, resulting in a performance impact on the Endpoint Security (HX) server as it gathers all the IOCs.
Replacement scenarios
The following scenarios are explained in detail.
New Central Management System appliance, New Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a large history of alerts: In this scenario, a large delta may accrue for all of the historic and incoming alerts on the Trellix detection devices.
New Central Management System appliance, existing Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a high volume of alerts: In this scenario, a large delta may accrue while the Central Management System appliance is offline with a large influx of alerts.
New Central Management System appliance, existing Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a low volume of alerts: The Bookmark ID may be greater than the actual latest Alert ID which can potentially result in missed alert IOCs.
Existing Central Management System appliance, New Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a large history of alerts: A large delta may accrue for all of the historic and incoming alerts on the Trellix detection devices.
Replacement scenario 1: New Central Management System appliance, New Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a large history of alerts
When a customer installs a new Central Management System appliance (new purchase, model upgrade or RMA) and a new Endpoint Security (HX) server (new purchase, model upgrade or RMA) in an existing Network Security/Email Security — Server/File Protect/Malware Analysis environment:
The Central Management System appliance Alert ID is zero
The Endpoint Security (HX) server Bookmark ID zero
The Network Security/Email Security — Server/File Protect/Malware Analysis latest alert ID is a large number
The Central Management System appliance will aggregate all of the existing alert data and send notifications for all of the Alert IDs to the managed Endpoint Security (HX) server. The Endpoint Security (HX) server will poll the Central Management System appliance for all of the alerts between zero and the latest Alert ID. This could result in a large delta and could impact the performance of the Endpoint Security (HX) server. The process of the Endpoint Security (HX) server Bookmark ID catching up to the latest Alert ID can take many hours or days depending on the amount of alert data present on the Central Management System appliance. This can result in a signification delay in the Endpoint Security (HX) server receiving the latest, most relevant IOCs, causing missed malware detection on the endpoints. To prevent this, advance the Endpoint Security (HX) server Bookmark ID to a recent Alert ID (see steps below) before attaching the Endpoint Security (HX) server to the Central Management System appliance.
Replacement scenario 2: New Central Management System appliance, existing Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a high volume of alerts
When a customer installs a new Central Management System appliance (new purchase, model upgrade or RMA) in an existing Endpoint Security (HX) server and Network Security/Email Security — Server/File Protect/Malware Analysis high volume environment:
The Central Management System appliance Alert ID is zero
The Endpoint Security (HX) server Bookmark ID is a large number
The Network Security/Email Security — Server/File Protect/Malware Analysis latest alert ID is a larger number
The Central Management System appliance will aggregate all of the existing alert data and send notifications for all of the Alert IDs to the managed Endpoint Security (HX) server. The Endpoint Security (HX) server will poll the Central Management System appliance for all of the alerts between the last Bookmark ID and the latest Alert ID. For a high-volume alert environment, this delta can be large depending upon how long the Central Management System appliance is offline and the rate of alert influx. This could result in a large delta and could impact the performance of the Endpoint Security (HX) server. The process of the Endpoint Security (HX) server Bookmark ID catching up to the latest Alert ID can take several hours depending on the amount of alert data. This can result in a delay in the Endpoint Security (HX) server receiving the latest, most relevant IOCs.
Replacement scenario 3: New Central Management System appliance, existing Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a low volume of alerts
When a customer installs a new Central Management System appliance (new purchase, model upgrade or RMA) in an existing Endpoint Security (HX) server and Network Security/Email Security — Server/File Protect/Malware Analysis low volume environment:
The Central Management System appliance Alert ID is zero
The Endpoint Security (HX) server Bookmark ID is a larger number
The Network Security/Email Security — Server/File Protect/Malware Analysis latest alert ID is a large number
The Central Management System appliance will aggregate all of the existing alert data and send notifications for all of the Alert IDs to the managed Endpoint Security (HX) server. In rare cases, the Endpoint Security (HX) server Bookmark ID could be greater than the latest Central Management System appliance Alert ID. The Endpoint Security (HX) server will poll the Central Management System appliance for the larger Bookmark ID and will not receive an IOC from the Central Management System appliance until the Central Management System appliance Alert ID advances to equal the Bookmark ID. This could result in missing IOCs from alerts with Alert IDs below the Endpoint Security (HX) server Bookmark ID, as well as missing malware detection on the endpoints. You can modify the Endpoint Security (HX) server Bookmark ID to equal a recent Alert ID (see steps below) before attaching the Endpoint Security (HX) server to the Central Management System appliance to prevent this.
Replacement scenario 4: Existing Central Management System appliance, New Endpoint Security (HX) server, existing Network Security/Email Security — Server/File Protect/Malware Analysis with a large history of alerts
When a customer installs a new Endpoint Security (HX) server (new purchase, model upgrade or RMA) in an existing Central Management System appliance and Network Security/Email Security — Server/File Protect/Malware Analysis environment:
The Central Management System appliance latest Alert ID is a large number
The Endpoint Security (HX) server Bookmark ID zero
The Network Security/Email Security — Server/File Protect/Malware Analysis latest alert ID is a large number
The Central Management System appliance will send notifications for all of the Alert IDs to the managed Endpoint Security (HX) server. The Endpoint Security (HX) server will poll the Central Management System appliance for all of the alerts between zero and the latest Alert ID. This could result in a large delta and could impact the performance of the Endpoint Security (HX) server. The process of the Endpoint Security (HX) server Bookmark ID catching up to the latest Alert ID can take many hours (or days) depending on the amount of alert data present on the Central Management System appliance. This can result in a signification delay in the Endpoint Security (HX) server receiving the latest, most relevant IOCs, causing missed malware detection on the endpoints. To prevent this, you should advance the Endpoint Security (HX) server Bookmark ID to a recent Alert ID (see steps below) before attaching the Endpoint Security (HX) server to the Central Management System appliance.
Modifying the Endpoint Security (HX) server Bookmark ID
For Scenarios 1,3 and 4, the Endpoint Security (HX) server Bookmark ID should be set to a recent Central Management System appliance Alert ID before adding the Endpoint Security (HX) server to the Central Management System appliance. To determine the most recent Alert ID on the Central Management System appliance, run the following CLI Command:
sh log matching \bnotifyd\b.*\bdone_notify_alerts\b
In the example below, the Endpoint Security (HX) server Bookmark ID can be set to '5071' to receive the latest IOC from the Central Management System appliance. However, depending on the scenario, the Endpoint Security (HX) server could have a large delta or could be missing out on recent IOCs. To get a better Bookmark ID starting point, log into the Central Management System appliance UI, navigate to the Alerts/Alerts page, set the inline filter Date Range to 'Past 1 Week' (or any desired time-frame), and apply the filter. The total number of alerts for this time-frame can be found in the upper left-hand corner of the alerts display. Subtract this number from the most recent Alert ID and set the Endpoint Security (HX) server Bookmark ID to this number to gather the past weeks IOCs. For instance, if the Central Management System appliance displays 50 alerts for the selected date range, the Bookmark ID can be set to '5021'. The Endpoint Security (HX) server should be added to the Central Management System appliance. The Endpoint Security (HX) server will begin to gather the IOCs from the alerts from 5021 through the current Central Management System appliance Alert ID as soon as it receives the first Alert notification of the most current Alert ID from the Central Management System appliance.
Example
dresden # sh log matching \bnotifyd\b.*\bdone_notify_alerts\b
Jul 11 12:51:51 dresden notifyd[28468]: tid 28468: [notifyd.INFO]: SQL:select * from done_notify_alerts('{5069} ')
Jul 11 12:53:21 dresden notifyd[28468]: tid 28468: [notifyd.INFO]: SQL:select * from done_notify_alerts('{5070} ')
Jul 11 12:54:22 dresden notifyd[28468]: tid 28468: [notifyd.INFO]: SQL:select * from done_notify_alerts('{5071} ')