Trellix EDRF provides two distinct historical search features depending on the deployment environment:
Historical Search for EDRF Cloud: Access from the EDR user interface via the Monitoring and Device Search dashboards.
Historical Search for EDRF On-Prem: Use the Historical Search Module, which is installed on the Endpoint Security (HX) server.
Trellix EDR collects traces, processes, and correlate the data to provide a view of everything that was happening on endpoints. When there is a suspicious activity on the endpoint and you want to know the details of the activities such as scripts executed, malicious files extracted, external connections established, etc. on the endpoint, you can search for malicious artifacts on the endpoint using Trellix EDR Device Search and Historical Search capabilities. This helps analyze how the threat occurred in the system and what triggered it. Historical data collected from a device provides a view of everything that was collected on a streaming basis.
Note
Trellix EDR for macOS does not support the MD5 and SHA1 hashes.
The available data can range from within the past four hours to maximum retention. The maximum retention time is based on the subscription you choose during the on-boarding process. The minimum time you can select is 30 days and the maximum is 90 days. If you want to change the retention time, contact the Trellix support center.
Following are the key capabilities available for searching the historical endpoint data: