This Trellix Endpoint Detection and Response - Cloud October 04, 2023 release includes a new Trellix EDR API.
Every update release is cumulative and includes all features and fixes from the previous release.
Trellix EDR Activity feed API is available
The new Trellix EDR Activity feed API replaces the existing activity feed scripts available. In this release, an API mechanism is enabled via Trellix gateway to push threat and case management events to your own S3 bucket and Syslog data sinks.
Regarding the scopes for Activity feed API:
If you are an existing user and already generated client credentials through Trellix Developer Portal, Trellix manually updates all client_types with the Activity feed API scopes automatically.
if you are a new user and never generated client credentials, reach out to Trellix Support and share the list of APIs you want to access.
Note
The data retention period for threat and case management events is 24 hours. If there are any issues with your data sink, make sure it's fixed in 24 hours. If you are unable to fix it in 24 hours, reach out to Trellix Support to increase the retention time to avoid any data loss.
For details about how to use the APIs and samples, see API sample for Activity feed.
Installation information
The Trellix Endpoint Detection and Response Installation Guide has all the information you need to install the product for the first time and to migrate from Trellix® Active Response.
Known issues
For a list of known issues in Trellix EDR, see KB91275.