EDRF On-prem deployment

Prev Next

EDRF On-prem provides an on-site architecture for organizations requiring local telemetry retention due to security, data sovereignty, or air-gapped network policies.

Unlike a cloud-based setup, an On-prem deployment requires you to plan and provision your own server infrastructure. This section details the architectural components, hardware specifications, and retention models required for deployment.

Note

We recommend working with Trellix Professional Services to design and implement a final architecture that meets your specific needs.

Virtualization requirements

Trellix provides the following components as Open Virtual Appliances (OVA):

  • Endpoint Security (HX) server

  • Data Exchange Layer (DXL) Broker

  • EDR Telemetry Store

Note

Trellix ePO - On-prem is not provided as a virtual appliance. You must install it on a virtual machine (VM) running Windows Server and Microsoft SQL.

Architecture overview

An EDRF On-prem environment relies on specific mandatory and supporting components to manage endpoints and store trace data.

Core components

  • Endpoint Security (HX) server delivers endpoint detection and response (EDR) capabilities to the Security Operations Center (SOC). It provides real-time visibility into endpoint processes and uses behavioral analysis to automatically detect advanced threats. You can use Endpoint Security (HX) to perform remote incident response actions, including Host containment, Remote shell, Triage, and Forensic data acquisition.

    The Endpoint Security (HX) server is available as a physical or virtual appliance. For more information about supported appliance models on Endpoint Security (HX), see Supported appliance models.

  • ePO - On-prem is a centralized management console that enables you to deploy, manage, and report on security products across your enterprise network.

    For more information about supported platforms for ePO, see the Trellix Knowledge Base article, Supported platforms for Trellix ePolicy Orchestrator - KB51569.

  • EDR Telemetry Store stores telemetry and trace data streamed from endpoints. This allows analysts to perform historical searches on past activity, even if an endpoint is offline.

    The EDR Telemetry Store is available as an Open Virtual Appliance (OVA). It runs OpenSearch on a CIS Level 1 hardened AlmaLinux operating system.

For large-scale deployments, these components ensure performance and availability:

  • Agent Handlers offload processing duties from the ePO - On-prem server. They manage Trellix Agent communication and handle repository requests.

    You can deploy Agent Handlers to:

    • Support large network environments.

    • Manage roaming endpoints

    For details, see Agent Handler server requirements.

  • Data Exchange Layer (DXL) brokers provide the foundation for the Data Exchange Layer, a near real-time communication fabric.

    The DXL enables you to:

    • Deliver trace data to the EDR Telemetry Store.

    • Perform reputation lookups for Threat Intelligence Exchange (TIE).

    • Execute ePO - On-prem agent wake-up calls.

    For details, see the Trellix Knowledge Base article, Supported platforms for Trellix Data Exchange Layer Broker - KB90421.

  • Threat Intelligence Exchange (TIE) servers establish a local, real-time file reputation cache. They enable dynamic reputation sharing and the ingestion of threat intelligence.

    By checking file reputation on the local network rather than the cloud, TIE servers allow you to:

    • Instantly verify file trust.

    • Accelerate threat detection.

    • Provide a customized defense.

    For details, see the Trellix Knowledge Base article, Supported platforms for Trellix Threat Intelligence Exchange Server - KB83368.

  • Trellix Agent acts as a local communication and content repository on a network segment. It caches updates, such as content files and packages, from the ePO - On-prem server or Agent Handler and distributes them to neighboring agents.

    Using a designated Trellix Agent enables you to:

    • Reduce network bandwidth usage across wide area network (WAN) links.

    • Accelerate content delivery to endpoints.

    For details, see Trellix Agent server requirements.