The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Upgrade multiple Trellix ESM s from version 10.x

Prev Next

Upgrade your Trellix ESM software to a new version.

If you are adding Trellix ESM devices for performance (not replication), make sure they are not configured as redundant during the upgrade process. They will be added after the upgrade is complete and the replication factor will not be changed. For example, you might have 4 Trellix ESM devices in your 10.x deployment. One is primary and three are redundant. In 10.x, each one is a copy of the primary so there are 4 copies of data. In 11.x, you could have all 4 in the cluster with a replication factor of 2. This would give you two copies of your data on 2 nodes for performance and high availability. To upgrade to this configuration, you would remove two redundant Trellix ESM devices from the existing installation, upgrade to the new version (which creates a cluster of 2 Trellix ESM devices), then manually add two Trellix ESM devices. Instructions for removing redundant devices are in the installation guide for your Trellix ESM current version.

The replication factor must be a multiple of the number of nodes (Trellix ESM devices). To add nodes for performance, they must be added in even numbers.

If you are repurposing an existing Trellix ESM device, get a model-specific ISO from the download site and deploy that first to "clean" the device. You must complete the first-time logon process after deploying the ISO and before adding the Trellix ESM device to a cluster.

Caution

When updating, all active collectors stop collecting data until you rewrite the device settings and roll out the policy.

  1. From the Trellix ESM dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png, then click System Properties .

  2. Click ESM Management.

  3. Select the Maintenance tab, then click Update ESM.

  4. In the Select Software Upgrade File window:

    • Select the upgrade file from the list, then click OK.

      Or

    • Click Browse to check for a software upgrade file obtained from the download site on your system and then, click Upload.

  5. In Proceed with Upgrade, click Yes to run the upgrade advisor.

    The System Advisor Upgrade Check window shows the available online and offline devices along with their respective status.

  6. Click Close in System Advisor Upgrade Check and then, in the Upgrade ESM Software window, click Yes to run the upgrade.

    1uzdmTThe Trellix ESM device restarts and all current sessions are disconnected while the upgrade is installed. If you encounter issues during an upgrade, you can restore the backup files or contact Support.

  7. Upgrade any redundant Trellix ESM devices by logging into each redundant device and repeating this process.

    1agZOUEach redundant Trellix ESM device is configured as part of a cluster with replication.

  8. When the upgrade process is complete, refresh the browser.

  9. Clear the browser cache to prevent issues at logon.

A rules update is automatically started after the upgrade. During the rules update:

  • The application is not available. Wait for the process to finish and refresh the page.

  • You might see error messages related to 'snowflex' and 'snowman'. Disregard the error messages.