To enable the EDRF Client to send trace data to the EDR Telemetry Store, you must configure the General and Streaming policies. Additionally, configure Detection, Investigation, and Remediation policies to enable threat detection, investigation, and response capabilities.
Note
Protection capabilities are provided through Trellix Endpoint Security (ENS). Deploy ENS on the endpoints and configure the required protection policies in ENS to enable protection features. For more information about configuring ENS policies, see the ENS documentation.
Configure the General policy
For more information about General policy settings, see General policy.
Log on to ePO - On-prem On-prem as an administrator.
Navigate to Menu → Policy → Policy Catalog.
From the Product list, select Trellix EDR with Forensics.
Expand the General category, then click Edit for the policy you want to configure.
Click Show Advanced to view all policy settings.
Verify that the following policy settings are enabled by default:
Trellix EDR with Cloud
Trellix EDR with Forensics Logging
Proxy Settings for EDR with Forensics
Disable the EDR Content Updates setting.
Note
Do not use the default setting in EDRF On-prem environment. The default setting allows endpoints to bypass the local server and fetch updates directly from the internet. Administrators must apply updates manually using the Client Task Catalog. For details, see Distribute EDRF content updates locally.
Click Save.
Distribute EDRF content updates locally
EDRF content packages improve detection capabilities and endpoint performance. These packages adjust data collection and streaming processes. They reduce the generated telemetry volume and improve visibility into endpoint actions.
Download new EDRF content packages from the Trellix download portal or Software Catalog.
In ePO, go to Menu → Main Repository and select Check In Package.
Click Choose File and select the downloaded content package.
Verify these settings:
Package info — Verify the package details.
Branch — Select the repository branch. Use the Evaluation branch to test new packages.
Note
Move tested packages to the Current branch in the Main Repository.
Options — Select one of these actions:
Move the existing package to the Previous branch — This setting archives the current package when you check in a newer version. This option is only available for the Current branch.
Package signing — This field identifies if the package is from Trellix or a third party.
To update the content package, follow the steps mention in Deploy EDRF using ePO - On-prem using Client Task.
Configure the Streaming policy
On the Policy Catalog page, expand the Streaming category.
Click Edit for the policy you want to configure.
Verify that the following policy settings are enabled by default:
Enable Trace
Enable deep inspection of Windows API calls
Enable ETW-TI of Windows API calls
Send traces to Trellix EDR Cloud
Alerts Streamed to EDR Cloud
Note
Do not disable the Send traces to Trellix EDR Cloud or Alerts Streamed to EDR Cloud settings. The endpoint client uses these services to send trace data to the Data Exchange Layer (DXL). The DXL then routes telemetry to your local on-premises telemetry store. If you disable these settings, you disrupt the trace data flow.
You can Configure the storage and interval settings for the trace data as needed.
Click Save.
For more information about Streaming policy settings, see Streaming policy.
Configure the Detection policy
On the Policy Catalog page, expand the Detection category.
Click Edit for the policy you want to configure.
Verify that the following policy settings are enabled:
Enable Real-Time Indicator Detection
Capture Network Connection Events
Capture DNS Events
Capture URL Events
You can add process and trace rule exclusions to limit the amount of telemetry data generated by the system.
Click Save.
For more information about Detection policy settings, see Detection policy.
Configure the Investigation policy
On the Policy Catalog page, expand the Investigation category.
Click Edit for the policy you want to configure.
Verify that the following policy settings are enabled by default:
Enable process history
Enable Network flow collector
You can exclude processes from network collection by entering their full file path on Windows endpoints. This prevents the system from collecting TCP and UDP information for these specific processes.
Click Save.
For more information about Investigation policy settings, see Investigation policy.
Configure the Remediation policy
On the Policy Catalog page, expand the Remediation category.
Click Edit for the policy you want to configure.
Verify that the following policy settings are enabled by default:
Enable the option to display the message on containment actions
You can exclude application paths from containment for Windows, macOS or Linux endpoints.
For more information about Remediation policy settings, see Remediation policy.