You can install Trellix EDR locally on the ePO - On-prem server.
Make sure that you have ePO - On-prem 5.10.x or later installed.
For information about deploying Trellix Agent, see the Trellix Agent Installation Guide.
Make sure to install the DXL broker extension before you install the Trellix EDR 4.1.x client.
On Software Catalog, you can see the following options when there is an update in release version — <major>.<minor>.<patch>.<build>.
The Update option is displayed only when there is a change in the "<patch> or <build>" or "<patch>.<build>".
The Check-in option is displayed only when there is a change in the "<major> or <minor>" or "<major>.<minor>"
Important
If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
Upon installation or upgrade of the Trellix EDR client, you might have to reboot the client system.
Note
You can link multiple ePO - On-prem environments to a single tenant by following the same steps from 6 to 10.
Log on to Trellix EDR as administrator.
Click the configuration icon on the top-right corner to access the Configuration page.
On the Configuration page, select Use Trellix ePO - On-prem for management.
Important
Make sure you select the correct configuration. This setting can only be changed with the assistance of Customer Support.
Click Save, then click Continue to confirm the configuration.
In the View account settings section, you can opt to share telemetry data by selecting I choose to share telemetry data (defined below) with Trellix and its third-party processors, then click Save.
Check in the Trellix EDR extension:
Log on to ePO - On-prem as administrator.
Select Menu → Software → Software Manager / Software Catalog, then under Product Categories search for Trellix EDR.
Select the Trellix Endpoint Detection & Response product to view the list of available components.
Note
Select the appropriate Trellix EDR client package for Windows, Linux, or macOS endpoints.
For the Trellix EDR component, under Actions click Check In.
Read the Trellix End User License Agreement and select I accept the terms in the license agreement checkbox.
After checking in the Trellix EDR extension, all dependent extensions and packages are installed.
ePO - SaaS Cloud Bridge
Trellix EDR Endpoint Snapshot Tool
Trellix EDR
Trellix Data Exchange Layer extensions
Trellix Data Exchange Layer broker extensions
Trellix EDR Client
Trellix EDR Client Package
Add your Trellix EDR account credentials to ePO - SaaS Cloud Bridge:
From ePO - SaaS, select Menu → Configuration → Appliance and Server Registration.
Click Add to add a new registration token.
Select the Client type as Trellix ePolicy Orchestrator - SaaS.
Type the number of appliances or servers you want to register in the Number of clients field and click Save.
To view the generated token, expand Trellix ePolicy Orchestrator - SaaS under Servers. Note down the registration token.
Perform one of these actions if you want to revoke the token:
From the token list, click Revoke under Actions.
Select the token, then select Revoke from the Take Action drop-down list in the token details pane.
To revoke the token from a client - select a token from the token list, then select one or more clients from the Registered Clients pane and select Revoke from the Take Action drop-down list.
Log on to the ePO - On-prem server as an administrator. Select Menu → Configuration → Server Settings, then select Trellix ePO-SaaS Cloud Bridge from Setting Categories. The Trellix ePO-SaaS Cloud Bridge Server Settings page displays these options:
Status— Displays the status of the connection. See Status Messages for detailed status information.
Note
Before you configure your connection, the status is
This server is not linked with Trellix ePO-SaaS.Tenant ID — Displays the tenant ID of the linked ePO-SaaS account.
Cloud Bridge Client ID — Displays the Client ID associated with the token.
From the Trellix ePO-SaaS Cloud Bridge Server Settings page, click Edit.
Enter the Registration Token generated from Step a.
In the ePO Logon URL section, enter the ePO - On-prem URL which you are using to access the on-premises ePO - On-prem server.
Click Save.
Note
The Cloud Bridge settings page now contains a field ePO Logon URL which can be seen only from ePO - On-prem 5.10.0 Update 7 onwards. This URL is added to the allowed URL list in Identity and Access Management (IAM). This is needed for IAM to redirect the user to the on-premises ePO - On-prem after authentication using Log On With ePO - SaaS feature.
The ePO - SaaS Cloud Bridge Server Settings page displays the status as This server is actively linked, and the linked account as the email address for the Trellix account:
Status — After configuration, above the Refresh button, the status is
This server is actively linked.Trellix ePO-SaaS Tenant ID — The ID for the particular ePO - SaaS tenant.
Cloud Bridge Client ID — The Client ID associated with the token.
ePO Logon URL — Your ePO - On-prem URL which you are using to access the ePO - On-prem server.
Your ePO - On-prem server is now connected to the ePO - SaaS account.
Note
You might see some error messages while linking your ePO - On-prem account with the ePO - SaaS account. For more information, see Common error messages while linking ePO - On-prem with ePO - SaaS account.
To view the connected servers in ePO - SaaS, go to Menu → Configuration → Appliance and Server Registration.
Click Trellix ePolicy Orchestrator - SaaS under Servers.
The Used Clients column displays the number of clients connected to ePO - SaaS.
The Correct DXL Cloud Databus URL server task in ePO automatically configures the DXL Cloud Databus URL based on your region. By default, this server task runs daily to verify and correct the URL.
To modify the server task:
In ePO, go to Menu > Configuration > Server Tasks.
In the Server Tasks page, locate the Correct DXL Cloud Databus URL server task, and then select Edit in the Actions column.
On the Description tab, modify the Name and Notes.
Enable or disable the Schedule Status, and then select Next.
On the Actions tab, select Next.
On the Schedule tab, choose the schedule type, start date, end date, and schedule time, and then select Next.
On the Summary tab, review the settings, and then select Save.
To update the data center location manually follow these steps.
In ePO, go to Menu > Configuration > Server Settings.
In the Setting Categories pane, select DXL Cloud Databus.
Click Edit and enter the URL for your server destination.
The following lists the DXL Cloud Databus URLs by data center location.
US-West data center —
https://api.soc.trellix.com/cloudproxy/databus/produceUS-East data center —
https://api.soc.us-east-1.trellix.com/cloudproxy/databus/produceFrankfurt data center —
https://api.soc.eu-central-1.trellix.com/cloudproxy/databus/produceCanada data center —
https://api.soc.can-central-1.trellix.com/cloudproxy/databus/produceAsia Pacific South data center —
https://api.soc.ap-south-1.trellix.com/cloudproxy/databus/produce
Click Save.
An incorrect URL configuration in the DXL Cloud Databus causes Trellix EDR features to become non-functional or display incomplete data.
If you are unsure of your data center location, contact Trellix Support and provide your tenant ID.
Install or upgrade the DXL broker to version 5.0.x or later.
For details about installing or upgrading DXL broker, see Trellix Data Exchange Layer Installation Guide.
Deploy the Trellix EDR client to devices:
On ePO - On-prem, select Menu → Product Deployment, then click New Deployment.
Enter a name and description for the deployment task.
Select the appropriate Trellix EDR client package for Windows, Linux, or macOS endpoints as the software package.
Click Select Individual Systems.
From System Tree, on the System Selection page, select the devices where you want to deploy the Trellix EDR client, then click OK.
Click Run Immediately to start the deployment task immediately.
Click Save.
Note
When installing Trellix EDR client on macOS endpoints, the endpoint user is prompted with pop-ups to grant permission for TrellixSystemExtensions on the general tab from the security and privacy page. Also, you must allow full disk access for TrellixSystemExtensions and fmpd on the privacy tab.
On Trellix EDR, click the configuration icon to access the Configuration page:
Select Install components, then click Done.
Select Configure data sources, click Trellix ePO - On-prem, and verify whether the connection status is green.
Check that all Trellix EDR basic components are installed and the product is connected to ePO - On-prem.
To install Trellix EDR on another ePO - On-prem system, follow steps 6 through 10.