Trellix Agent 5.8.4 release includes feature enhancements and resolved issues.
Release details
For release date and build number details of 5.8.x, see KB51573.
Rating
The rating defines the urgency for installing this update.
This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product.
What's new in Trellix Agent 5.8.4
New features
System Information Reporter (SIR) integration with Trellix Agent — Trellix Agent 5.8.4 now includes the System Information Reporter (SIR), a new module that uses ePO policies to collect detailed data from endpoints, such as installed software, running processes, and registry values.
A new Trellix Agent for Operational Technology (OT) package, that is now available only for Windows systems and supports ePO - On-prem, automatically installs SIR, simplifying deployment in environments requiring reduced third-party software validation.
The standard Trellix Agent for Windows package does not install SIR by default, but you can install it by adding the /installsir command-line parameter during deployment.
Trellix Agent 5.8.4 automatically upgrades existing SIR to version 1.0.4. For more details, see the SIR Release Notes and Product Guide.
Upgraded to OpenSSL-1.0.2zl and LibCurl version to 8.12.0. For details, see KB96878.
The 5.8.3 MsgBusCertUpdater package is updated with new certificates to ensure compatibility with Trellix point products and services. For more details, see KB14338.
Trellix Agent compatibility with other products
To view the list of products and versions that are compatible with Trellix Agent 5.8.x release, see KB96739.
Resolved issues in Trellix Agent 5.8.4
This release resolves known issues.
Table 1. Installation
Reference | Resolution |
|---|---|
MA-16287 | Fixes the issue where the product upgrade to a higher version when the deployment task specified a lower version and auto-update was disabled due to the timing of policy enforcement and version checks. |
MA-16578 | Fixes the issue where VDI mode was removed during an Agent upgrade to version 5.8.3. |
Table 2. Product manageability
Reference | Resolution |
|---|---|
MA-14470 | Fixes the issue where the |
MA-15910 | Fixes the issue where clients failed to apply a new policy with updated Relay Server settings, causing them to continue communicating with the old Relay servers. |
MA-15967 | Fixes the issue where the VDI mode setting was disabled on agents after migrating them from an ePO On-prem to SaaS using the migration extension. |
MA-16048 | Fixes the issue where the agent startup script on Linux incorrectly generated the error "root is not in the sudoers file", even on properly configured systems. |
MA-16173 | Fixes the issue where the ePO console intermittently displayed "STOPLOOP" instead of the correct version of the product. |
MA-16174 | Fixes the issue where the systemctl command on RPM-based Linux systems incorrectly reported the agent service status as "failed" or "inactive" after upgrading to version 5.8.3. |
MA-16256 | Fixes the issue that prevented cmdagent commands from executing on Linux systems with SELinux enabled. |
MA-16553 | Fixes the performance issue where the Agent's health check script on Linux systems caused excessive LDAP and DNS queries to Domain Controllers, by adhering to UNIX standards. |
MA-16559 | Fixes the issue on Linux platforms where the OS OEM identifier was incorrectly reported with a preceding "Name =" and was missing the full version details after Trellix Agent upgrade to version 5.8.3. |
MA-16603 | Fixes the issue where Trellix EDR with Forensics platform traces were not sent to the cloud because the agent failed to fetch the token due to expired or revoked credentials. |
MA-16750 | Fixes the issue where Ubuntu servers were reported as 'Workstation' instead of 'Server' in the ePO console. |
MA-16753 | Fixes the agent registration flow to mitigate IAM server overload during network connectivity issues. |
Known issues
For a list of current known issues, see: Trellix Agent 5.8.x Known Issues (KB96738).