Prepare devices to function with the new version of Trellix ESM.
Read the release notes for important information about changes in this version.
If you recently upgraded your Trellix ESM software, make sure the database rebuild is complete. If you can log on to the Trellix ESM, the rebuild is complete.
Upgrade Trellix ESMs to the new version.
Download the update files from the Trellix download site.
Upgrade devices in the order indicated. Not following this sequence might cause configuration issues.
Note
On new installations, the default configuration inserts events from the most recent 24-hour period. You can change this setting (<device> Properties → Events, Flows, and Logs).
Download the device update files.
Go to the Trellix download site.
Click Download, enter your grant number and email address, type the CAPTCHA characters as displayed, then submit.
Select SIEM Mangement Solutions (left menu) and select a device.
Download the update file for each type of device in your system.
Note
Trellix ESM - ACE, Trellix DSB, Trellix ESM - ELM, Trellix ESM - ELS, and SIEM Collector use the same upgrade file.
Make sure that you have communication with each device in the system.
From the dashboard, click
and select Configuration.Select a device from the device tree and click Properties.
.png)
Click Status and check that the device is communicating.
Update Data Streaming Bus (if applicable)
Warning
Do not close or refresh your browser during the update process. Doing so prevents the update from finishing. If the update process is interrupted, restart the device to complete the process.
From the navigation menu
, select Data Streaming Bus.Right-click the Trellix DSB and click Settings.
Expand Update Software File.
Click Upload and browse to the update file.
Select the update file and click Continue.
User input is paused while the Trellix DSB is updated and restarted.
If you are updating a single Trellix Enterprise Security Manager - Enterprise Log Manager:
From the dashboard, select the Trellix Enterprise Security Manager - Enterprise Log Manager device on the system navigation tree, then click the Properties icon.
Click <device> Management, then select the Maintenance tab.
Click Update <device>.
Select an update from the table or click Browse to locate the update file on your local system.
Click OK.
Go to ELM Properties → ELM Information.
If the message Database is rebuilding appears in the Active Status field, do not stop or start the ELM database. The system indexes all new ELM data on the sending device before sending that data to the ELM.
If you are updating redundant Trellix Enterprise Security Manager - Enterprise Log Manager devices:
Update the standby Trellix Enterprise Security Manager - Enterprise Log Manager.
Update the active Trellix Enterprise Security Manager - Enterprise Log Manager.
On the system navigation tree, select the standby ELM and go to ELM Properties → ELM Redundancy → Return to Service.
Go to ELM Properties → ELM Information and click Refresh. Both the active and standby ELMs display an OK status.
If the standby Trellix Enterprise Security Manager - Enterprise Log Manager displays a Not OK status, click Refresh again. After a few minutes, the standby Trellix Enterprise Security Manager - Enterprise Log Manager status changes to OK, redundant ELM resync is 100% complete. You might need to click Refresh several times.
Update your Trellix Enterprise Security Manager - Enterprise Log Search.
From the dashboard, select the Trellix ESM - ELS device on the system navigation tree, then click the Properties icon.
Click <device> Management, then select the Maintenance tab.
Click Update <device>.
Select an update from the table or click Browse to locate the update file on your local system.
Click OK.
Update Trellix Enterprise Security Manager - Event Receiver, Trellix ESM - ACE, and Trellix Application Data Monitor devices.
Important
If your system includes high availability receivers, use the Update high availability receivers process.
From the dashboard, select the device on the system navigation tree, then click the Properties icon.
Click <device> Management, then select the Maintenance tab.
Click Update <device>.
Select an update from the table or click Browse to locate the update software on your local system.
Click OK.
Wait for the update process to finish (which can take several hours) then verify that the Trellix ESM can communicate with the devices.
Write device settings.
Note
You must write out settings regardless of the number of devices in your system.
From ESM Properties, select Clustering.
Select the primary Trellix ESM device.
Make a minor change to enable the Write button. For example, type an extra digit in the port number and then remove it.
Click Write.
If you are upgrading from one major version to another (10.x to 11.x, for example) rekey all peripheral devices (ESM Properties → ESM Management → Key Management → Regenerate SSH).
Apply updated rules.
On the system navigation tree, select the Trellix ESM device, then click the Properties icon .
.png)
On the System Information page, click Rules Update, then click Check Now or Manual Update.
Browse to the update file, click Upload, then click OK.
Write settings to the Trellix Enterprise Security Manager - Event Receiver or Trellix ESM/Event Receiver combo.
On the dashboard, select the device in the system navigation tree, then click the Properties icon.
Click Data Sources → Write.
Click Vulnerability Assessment → Write.
Write settings to the Trellix ESM - ACE.
On the dashboard, select the device in the system navigation tree, then click the Properties icon.
Click Correlation Management → Write.
If the Trellix ESM - ACE is being used in Historical Mode, click Historical → Enable Historical Correlation → Apply. If it's already selected, deselect it and click Apply, select it again and click Apply.
Click Rule Correlation, select Enable Rule Correlation, and click Apply. If it's already selected, deselect it and click Apply, select it again and click Apply.
Write settings to Trellix Application Data Monitor.
On the dashboard, select the device in the system navigation tree, then click the Properties icon.
.png)
Click Virtual Devices → Write.
For database servers: Click Database Servers → Write.
Roll out policy.
If you have a device configured to send events to a Trellix Enterprise Security Manager - Enterprise Log Manager, sync the Trellix Enterprise Security Manager - Enterprise Log Manager (Device Properties → Device Configuration → Sync ELM).
q2XKy
: