FAQs for Data Exchange Layer
Technical Articles ID:
KB90414
Last Modified: 2022-09-16 18:57:58 Etc/GMT
Last Modified: 2022-09-16 18:57:58 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
FAQs for Data Exchange Layer
Technical Articles ID:
KB90414
Last Modified: 2022-09-16 18:57:58 Etc/GMT EnvironmentData Exchange Layer (DXL) 5.x, 4.x
Summary
This article is a consolidated list of common questions and answers; it is intended for users who are new to the product, but can be of use to all users. Recent updates to this article
How do I get the DXL client? The DXL client is automatically installed on managed systems with McAfee Agent 5.6.0 or later, and automatically connects to a DXL broker in your environment. DXL services run as part of McAfee Agent services. The DXL client is no longer installed with the DXL server and brokers. If there is no broker present, the DXL client is idle until a broker is available for it to connect to. Beginning with DXL 5.0, DXL releases include only the server-related components such as the DXL brokers and the DXL extensions for ePolicy Orchestrator (ePO). How can I see the DXL client version that I have installed? From the Windows Taskbar, click the shield icon and then click About. How do I deploy brokers only on systems with specific operating systems? In ePO 5.x and MA 5.x and later, when you deploy a broker using a Product Deployment task, the deployment task does not consider the Target platform option on the Product Deployment page. (The Target platform is the operating system.) The brokers are installed on all supported systems, regardless of the operating system selection. To ensure that the brokers are installed only on those systems you want, there are two available workarounds. For details, see: KB91361 - The DXL broker is deployed on Windows servers even though the Windows platform option is not selected in the ePO Product Deployment task Upgrading DXL How do I upgrade to a newer version of a DXL client? The DXL client is automatically updated on managed systems with McAfee Agent 5.6.0 or later. Are there any extension version restrictions I must be aware of? The DXL extension version in your upgrade must be the same or newer than the DXL broker version you are using. You can't install an older extension version with a newer broker version. Are there any considerations when I upgrade the DXL C++ client? Yes. When you upgrade the DXL C++ client on Windows from a version earlier than 2.1.0, you must first upgrade to any version between 2.1.0 and 4.0.0 before you upgrade to 4.1.0 or later. Do I need to install every hotfix for my version of DXL, or just the latest hotfix? All hotfix releases are cumulative; you need to install only the latest release to receive all past issue resolutions. Are there any extension version restrictions I need to be aware of? The DXL extension version in your upgrade must be the same or newer than the DXL broker version you use. You can't install an older extension version with a newer broker version. Broker and client connectivity How can I see if the Client and DXL broker are connected?
Configuring DXL brokersFrom the Windows Taskbar, click the shield icon and then click About. The Data Exchange Layer section shows broker connectivity information. If the Client and DXL broker are not connected, see the Data Exchange Layer Installation Guide. The Guide contains information about how to verify an install or update. It also includes instructions about how to check for and solve connection issues. To find the installation guide for your version, go to the Product Documentation site. Can I specify which brokers are used with specific DXL clients?
Yes. Use the DXL client policy in ePO. Endpoints can be assigned policies that use certain brokers or hubs, or can be restricted to connecting to only certain brokers or hubs. How many brokers do I need? This number is often determined by two considerations. Specifically, how you plan to connect major sites together, and where you need redundancy in the fabric to ensure site-to-site connectivity. DXL automation features How do I use the DXL remote commands? Remote commands that are exposed in ePO or Security Innovation Alliance Partner products can be called directly over DXL. Invoking remote commands over DXL is useful with automation tasks, whether they are user-driven (orchestrated), or performed without user involvement (automated). For example, DXL can generate an ePO Threat Event, or a DXL event on any topic using an Automatic Response Action. For information about using remote commands, see the Data Exchange Layer Product Guide. To find the product guide for your version, go to the Product Documentation site. Affected ProductsLanguages:This article is available in the following languages: |
|