This Trellix Endpoint Detection and Response - Cloud June 04, 2024 release includes Trellix EDR Activity Feed support for webhook sink, modification in the Syslog certificate configuration, and an update in the identity issuers.
Every update release is cumulative and includes all features and fixes from the previous release.
The Trellix EDR Activity feed API is available for webhook sinks
The new Trellix EDR Activity feed API replaces the existing activity feed scripts available. In this release, an API mechanism is enabled through the Trellix gateway to push threat and case management events to your webhook, S3 bucket, and Syslog data sinks. Also, the syslog sink can now be configured through single and multichain certificates in base64 encoded format. For more details, see API sample for Activity Feed.
Regarding the scopes for Activity feed API:
If you are an existing user and already generated client credentials through Trellix Developer Portal, Trellix manually updates all client_types with the Activity feed API scopes automatically.
if you are a new user and never generated client credentials, reach out to Trellix Support and share the list of APIs you want to access.
Note
The data retention period for threat and case management events is 24 hours. If there are any issues with your data sink, make sure it's fixed in 24 hours. If you are unable to fix it in 24 hours, reach out to Trellix Support to increase the retention time to avoid any data loss.
For details about how to set up a sample webhook server, use the APIs and query samples, see Set up a webhook controller, API sample for Activity feed, and Trellix EDR APIs for single customers from Trellix Endpoint Detection and Response Product Guide and Trellix Developer Portal.
An update made in the Trellix EDR identity issuers
The IAM cloud URL is now updated from mcafee domain (https://iam.mcafee-cloud.com) to Trellix domain (https://iam.cloud.trellix.com). However, the URL https://iam.mcafee-cloud.com will be supported till November 1st, 2024 and post that Trellix no longer supports this mcafee domain issuer.
This release supports the following IAM issuers:
https://auth.trellix.comhttps://iam.cloud.trellix.com
Installation information
The Trellix Endpoint Detection and Response Installation Guide has all the information you need to install the product for the first time and to migrate from Trellix® Active Response.
Known issues
For a list of known issues in this product release, see KB91275.