Manual upgrade from Trellix EDR to EDRF

Prev Next

The manual upgrade process allows you to selectively upgrade specific Trellix EDR policies to EDRF policies.

To manually upgrade:

  1. Log in to ePO - On-prem as an administrator.

  2. Navigate to MenuPolicyPolicy Catalog.

  3. Select Trellix EDR with Forensics from the product list.

  4. Identify the Trellix EDR policy you wish to upgrade and find its corresponding policy in EDRF.

  5. Customize the settings to match your existing Trellix EDR policy.

  6. Save the policy.

Note

You must create a new policy in each mapped EDRF category to implement the policies. For example, if your Trellix EDR policies are linked to the General category in EDRF, you would create and customize a new General policy in EDRF.

The following table maps Trellix EDR policies to their corresponding categories within the EDRF policy framework. To implement these policies in EDRF, you must create a new policy in each mapped category.

Trellix EDR policy

Corresponding Trellix EDR with Forensics policy mapping fields

General

General > Trellix EDR Content Updates

Enable read-only for Trellix EDR data folders

General Policy Category > Self-Protection > Enable Self-Protection

Enable content updates

Enable content Updates

Content update method

NA

Check for content updates at an interval

Check for content updates at an interval

The maximum number of results returned by the Trellix EDR Real-time Search

Navigate to Investigation Policy Category > Real-Time Search > Maximum number of results returned by Real-time Search

Enable password to uninstall the Trellix EDR Client (Windows only)

General Policy Category > Self-Protection > Enable password to uninstall

Enter password

Enter password

Confirm password

Confirm password

System Info

Investigation > Real Time Search > System Information

System Information > Enable process history

Enable process history

Network Flow > Network Flow

Investigation > Real-Time Search > Network Flow

Enable the Network Flow collector

Enable Network flow collector

Enable Network Sniffing

Enable Network Sniffing

Maximum size (MB) of the device storage that can be used by the Network Flow collector

Maximum size of device storage that can be used by Network Flow collector in MB

Maximum percentage of the device storage that can be used by the Network Flow collector database

Maximum percentage of device storage that can be used by the Network Flow collector in percentage (%).

Maximum number of results returned by the Network Flow collector

Maximum number of results returned by the Network Flow collector

Collect TCP/UDP system process information (Windows Only)

Collect TCP/UDP system process information (Windows Only)

Exclude process(es) from collecting TCP/UDP information (Use ';' as separator) (Windows only)

Investigation Policy Category > Real-Time Search > Exclusions > Exclude process(es) from collecting TCP/UDP information (Use ';' as separator) (Windows only)

Network Flow > Quarantine Settings

Remediation > Containment Settings

Enable the option to display the message on quarantine actions

Enable the option to display the message on containment actions

Message to display on a device when it is quarantined (max: 3072 characters)

Message to display on a device when it is contained (max: 3072 characters)

Message to display on a device when it is removed from the quarantine (max: 3072 characters)

Message to display on a device when it is removed from the containment (max: 3072 characters)

Enable password to unquarantine the Trellix EDR client at endpoint (Windows only)

Enable password to uncontain the endpoint (Windows only)

Exclude application paths from quarantine for Windows (Use ';' as separator) (max: 3072 characters)

Exclude application paths from containment for Windows (Use ';' as separator) (max: 3072 characters)

Exclude application paths from quarantine for macOS (Use ';' as separator) (max: 3072 characters)

Exclude application paths from containment for macOS (Use ';' as separator) (max: 3072 characters)

File Hashing > File Hashing Settings

Investigation > Real Time Search > File Hashing

Enable File Hashing on the device (enables the Files collector and trigger)

Enable File Hashing on the device (enables the Files collector and trigger)

Maximum size (MB) of the device storage that can be used by the File Hashing collector

Maximum size (MB) of the device storage that can be used by the File Hashing collector

Maximum percentage of the device storage used by the File Hashing collector database.

Maximum percentage of the device storage used by the File Hashing collector database in percentage (%).

Maximum number of results returned by the File Hashing collector

Maximum number of results returned by the File Hashing collector

Hash strategy

Hash strategy

Pause File Hashing when the device is running out of battery life

Pause File Hashing when the device is running out of battery life

Time (in seconds) to delay the File Hashing process after booting the device

Delay File Hashing process after booting the device by in seconds

Maximum file size for hashing

Maximum file size for hashing in MB

File Hashing > Exclusions Settings

Investigation > Real-Time Search > Exclusions

Exclude file(s) on Windows (use ';' as separator) (max: 3072 characters)

Exclude file(s) on Windows (use ';' as separator) (max: 3072 characters)

Exclude file extension(s) on Windows (Use ';' as separator) (max: 3072 characters)

Exclude file extension(s) on Windows (Use ';' as separator) (max: 3072 characters)

Exclude path(s) on Windows (Use ';' as separator) (max: 3072 characters)

Exclude path(s) on Windows (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file extension(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file extension(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude path(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude path(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on macOS (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on macOS (Use ';' as separator) (max: 3072 characters)

Exclude files extension(s) on macOS (Use ';' as separator ) (max: 3072 characters)

Exclude files extension(s) on macOS (Use ';' as separator ) (max: 3072 characters)

Exclude path(s) on macOS (Use ';' as separator) (max: 3072 characters)

Exclude path(s) on macOS (Use ';' as separator) (max: 3072 characters)

Trace > Trace Scanner

Streaming > Trace > Trace Scanning

Enable the Trace

Enable the Trace

Log level

Log level

Report internal reputation failures to ePO

Report internal reputation failures to ePO

Enable deep inspection of Windows API calls

Enable deep inspection of Windows API calls

Maximum size (MB) of the device storage that can be used by the Traces

Maximum size (MB) of the device storage that can be used by the Traces in MB

Interval (in seconds) to send trace events to Trellix EDR cloud

Interval to send trace events to Trellix EDR cloud in Seconds

Include all ImageLoad events on Windows

Include all ImageLoad events on Windows

Trace > Trace Scanner

Streaming > Trace > Exclusion

Disabled trace rules on Windows (Use ';' as separator) (max: 3072 characters)

Disabled trace rules on Windows (Use ';' as separator) (max: 3072 characters)

Disabled trace rules on Linux (Use ';' as separator) (max: 3072 characters)

Disabled trace rules on Linux (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Windows (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Windows (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Linux (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude file(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude folder(s) on Linux (Use ';' as separator) (max: 3072 characters)

Exclude folder(s) on Linux (Use ';' as separator) (max: 3072 characters)

Disabled trace rules on Mac (Use ';' as separator) (max: 3072 characters)

Disabled trace rules on Mac (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Mac (Use ';' as separator) (max: 3072 characters)

Exclude process(es) by full path on Mac (Use ';' as separator) (max: 3072 characters)

Trace > AWS S3 Settings

Streaming > Trace > Trace Destination

Send traces to Trellix EDR cloud

Send traces to Trellix EDR cloud

Send traces to AWS S3 bucket

Send traces to S3 bucket

AWS Access Key ID

Access Key ID

AWS S3 bucket Secret Access Key

S3 bucket Secret Access Key

AWS S3 default Region Name

S3 default Region Name

AWS S3 bucket Name

S3 bucket Name

Interval (in seconds) to send trace events to AWS S3 bucket

Interval (in seconds) to send trace events to S3 bucket

Logger > Logging Settings

General > EDR Service Logging

Logger format

Logger format

Log level

Log level

Buffer size

Buffer size

Maximum size (MB) of the log file

Maximum size (MB) of the log file