The manual upgrade process allows you to selectively upgrade specific Trellix EDR policies to EDRF policies.
To manually upgrade:
Log in to ePO - On-prem as an administrator.
Navigate to Menu → Policy → Policy Catalog.
Select Trellix EDR with Forensics from the product list.
Identify the Trellix EDR policy you wish to upgrade and find its corresponding policy in EDRF.
Customize the settings to match your existing Trellix EDR policy.
Save the policy.
Note
You must create a new policy in each mapped EDRF category to implement the policies. For example, if your Trellix EDR policies are linked to the General category in EDRF, you would create and customize a new General policy in EDRF.
The following table maps Trellix EDR policies to their corresponding categories within the EDRF policy framework. To implement these policies in EDRF, you must create a new policy in each mapped category.
Trellix EDR policy | Corresponding Trellix EDR with Forensics policy mapping fields |
|---|---|
General | General > Trellix EDR Content Updates |
Enable read-only for Trellix EDR data folders | General Policy Category > Self-Protection > Enable Self-Protection |
Enable content updates | Enable content Updates |
Content update method | NA |
Check for content updates at an interval | Check for content updates at an interval |
The maximum number of results returned by the Trellix EDR Real-time Search | Navigate to Investigation Policy Category > Real-Time Search > Maximum number of results returned by Real-time Search |
Enable password to uninstall the Trellix EDR Client (Windows only) | General Policy Category > Self-Protection > Enable password to uninstall |
Enter password | Enter password |
Confirm password | Confirm password |
System Info | Investigation > Real Time Search > System Information |
System Information > Enable process history | Enable process history |
Network Flow > Network Flow | Investigation > Real-Time Search > Network Flow |
Enable the Network Flow collector | Enable Network flow collector |
Enable Network Sniffing | Enable Network Sniffing |
Maximum size (MB) of the device storage that can be used by the Network Flow collector | Maximum size of device storage that can be used by Network Flow collector in MB |
Maximum percentage of the device storage that can be used by the Network Flow collector database | Maximum percentage of device storage that can be used by the Network Flow collector in percentage (%). |
Maximum number of results returned by the Network Flow collector | Maximum number of results returned by the Network Flow collector |
Collect TCP/UDP system process information (Windows Only) | Collect TCP/UDP system process information (Windows Only) |
Exclude process(es) from collecting TCP/UDP information (Use ';' as separator) (Windows only) | Investigation Policy Category > Real-Time Search > Exclusions > Exclude process(es) from collecting TCP/UDP information (Use ';' as separator) (Windows only) |
Network Flow > Quarantine Settings | Remediation > Containment Settings |
Enable the option to display the message on quarantine actions | Enable the option to display the message on containment actions |
Message to display on a device when it is quarantined (max: 3072 characters) | Message to display on a device when it is contained (max: 3072 characters) |
Message to display on a device when it is removed from the quarantine (max: 3072 characters) | Message to display on a device when it is removed from the containment (max: 3072 characters) |
Enable password to unquarantine the Trellix EDR client at endpoint (Windows only) | Enable password to uncontain the endpoint (Windows only) |
Exclude application paths from quarantine for Windows (Use ';' as separator) (max: 3072 characters) | Exclude application paths from containment for Windows (Use ';' as separator) (max: 3072 characters) |
Exclude application paths from quarantine for macOS (Use ';' as separator) (max: 3072 characters) | Exclude application paths from containment for macOS (Use ';' as separator) (max: 3072 characters) |
File Hashing > File Hashing Settings | Investigation > Real Time Search > File Hashing |
Enable File Hashing on the device (enables the Files collector and trigger) | Enable File Hashing on the device (enables the Files collector and trigger) |
Maximum size (MB) of the device storage that can be used by the File Hashing collector | Maximum size (MB) of the device storage that can be used by the File Hashing collector |
Maximum percentage of the device storage used by the File Hashing collector database. | Maximum percentage of the device storage used by the File Hashing collector database in percentage (%). |
Maximum number of results returned by the File Hashing collector | Maximum number of results returned by the File Hashing collector |
Hash strategy | Hash strategy |
Pause File Hashing when the device is running out of battery life | Pause File Hashing when the device is running out of battery life |
Time (in seconds) to delay the File Hashing process after booting the device | Delay File Hashing process after booting the device by in seconds |
Maximum file size for hashing | Maximum file size for hashing in MB |
File Hashing > Exclusions Settings | Investigation > Real-Time Search > Exclusions |
Exclude file(s) on Windows (use ';' as separator) (max: 3072 characters) | Exclude file(s) on Windows (use ';' as separator) (max: 3072 characters) |
Exclude file extension(s) on Windows (Use ';' as separator) (max: 3072 characters) | Exclude file extension(s) on Windows (Use ';' as separator) (max: 3072 characters) |
Exclude path(s) on Windows (Use ';' as separator) (max: 3072 characters) | Exclude path(s) on Windows (Use ';' as separator) (max: 3072 characters) |
Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters) | Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude file extension(s) on Linux (Use ';' as separator) (max: 3072 characters) | Exclude file extension(s) on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude path(s) on Linux (Use ';' as separator) (max: 3072 characters) | Exclude path(s) on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude file(s) on macOS (Use ';' as separator) (max: 3072 characters) | Exclude file(s) on macOS (Use ';' as separator) (max: 3072 characters) |
Exclude files extension(s) on macOS (Use ';' as separator ) (max: 3072 characters) | Exclude files extension(s) on macOS (Use ';' as separator ) (max: 3072 characters) |
Exclude path(s) on macOS (Use ';' as separator) (max: 3072 characters) | Exclude path(s) on macOS (Use ';' as separator) (max: 3072 characters) |
Trace > Trace Scanner | Streaming > Trace > Trace Scanning |
Enable the Trace | Enable the Trace |
Log level | Log level |
Report internal reputation failures to ePO | Report internal reputation failures to ePO |
Enable deep inspection of Windows API calls | Enable deep inspection of Windows API calls |
Maximum size (MB) of the device storage that can be used by the Traces | Maximum size (MB) of the device storage that can be used by the Traces in MB |
Interval (in seconds) to send trace events to Trellix EDR cloud | Interval to send trace events to Trellix EDR cloud in Seconds |
Include all ImageLoad events on Windows | Include all ImageLoad events on Windows |
Trace > Trace Scanner | Streaming > Trace > Exclusion |
Disabled trace rules on Windows (Use ';' as separator) (max: 3072 characters) | Disabled trace rules on Windows (Use ';' as separator) (max: 3072 characters) |
Disabled trace rules on Linux (Use ';' as separator) (max: 3072 characters) | Disabled trace rules on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude process(es) by full path on Windows (Use ';' as separator) (max: 3072 characters) | Exclude process(es) by full path on Windows (Use ';' as separator) (max: 3072 characters) |
Exclude process(es) by full path on Linux (Use ';' as separator) (max: 3072 characters) | Exclude process(es) by full path on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters) | Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters) |
Exclude folder(s) on Linux (Use ';' as separator) (max: 3072 characters) | Exclude folder(s) on Linux (Use ';' as separator) (max: 3072 characters) |
Disabled trace rules on Mac (Use ';' as separator) (max: 3072 characters) | Disabled trace rules on Mac (Use ';' as separator) (max: 3072 characters) |
Exclude process(es) by full path on Mac (Use ';' as separator) (max: 3072 characters) | Exclude process(es) by full path on Mac (Use ';' as separator) (max: 3072 characters) |
Trace > AWS S3 Settings | Streaming > Trace > Trace Destination |
Send traces to Trellix EDR cloud | Send traces to Trellix EDR cloud |
Send traces to AWS S3 bucket | Send traces to S3 bucket |
AWS Access Key ID | Access Key ID |
AWS S3 bucket Secret Access Key | S3 bucket Secret Access Key |
AWS S3 default Region Name | S3 default Region Name |
AWS S3 bucket Name | S3 bucket Name |
Interval (in seconds) to send trace events to AWS S3 bucket | Interval (in seconds) to send trace events to S3 bucket |
Logger > Logging Settings | General > EDR Service Logging |
Logger format | Logger format |
Log level | Log level |
Buffer size | Buffer size |
Maximum size (MB) of the log file | Maximum size (MB) of the log file |