Consolidation of ESET Inspect into ESET PROTECT
We are consolidating ESET Inspect and ESET PROTECT into a single platform. ESET Inspect is no longer a standalone console but a set of EDR/XDR capabilities integrated in ESET PROTECT. ESET PROTECT continues as the single console for endpoint protection, detection and response.
•ESET Inspect EDR/XDR capabilities—Migrated to ESET PROTECT
•ESET Inspect console—Scheduled for termination. We communicate your termination date in advance, and access to the console ends on that date.
•ESET Inspect Connector—Remains installed on the endpoints as the EDR sensor
The consolidation applies to the cloud version only. ESET Inspect On-Prem is a standalone product and is not affected. |
Feature availability
The table shows where the ESET Inspect capabilities are available in ESET PROTECT:
ESET Inspect feature |
ESET PROTECT feature |
|---|---|
Incidents |
|
ESET AI Advisor |
|
Detections |
Incidents and Advanced Search (Indicators) |
Rules |
|
Exclusions |
|
Blocked Hashes |
|
Terminal |
|
Search (low-level events) |
Rules, exclusions and blocked hashes are migrated automatically, including their tags. Executables marked as safe are converted to EDR Exclusions. No action is required.
Detections and Indicators
The data model for detections is redesigned. Legacy detections from ESET Inspect are not migrated. Indicators replace detections and are available in Advanced Search in ESET PROTECT. Investigation and response workflows are consolidated in Incidents.
Indicators are collected in parallel with legacy detections, so historical Indicator data is available in ESET PROTECT when the ESET Inspect console is terminated. Indicator collection requires ESET Inspect Connector version 3.0 or later.
Deprecated features
The following features are not migrated to ESET PROTECT and are not available after the ESET Inspect console is terminated:
•Mark as Safe for executables—Existing entries are converted to EDR Exclusions. Use EDR Exclusions for new suppression scenarios.
•Rerun rules and rerun tasks
•Scripts list
•Export of events in JSON format
•Tags for detections, processes, executables and blocked hashes—Tags for rules and exclusions are migrated together with those features.
•Comments for detections, executables and computers
•Marking detections as resolved—Resolution tracking is handled in Incidents.
Data that is not migrated
•Executables from the Executables list
•Tags for detections, processes, executables and blocked hashes
•Comments for detections, executables and computers
•Scripts from the Scripts list
Outbound integrations
Integrations that read detection data from the ESET Inspect backend are replaced by Indicator-based capabilities in ESET PROTECT. If you use these integrations, you keep access to ESET Inspect until the replacements are available and a migration period has passed.
Current integration (ESET Inspect data) |
Replacement (ESET PROTECT data) |
|---|---|
EDR Detection API (Incident Management in ESET Connect) |
Indicator API |
Incidents v3 API |
|
Application Control API |
|
Syslog export of ESET Inspect alerts |
Indicator-based Syslog export |
The replacement APIs are documented in the ESET Connect Online Help when they become available.
ESET Inspect Connector requirements
•Version 2.8 and earlier—Does not support Indicators, Incident correlation, or EDR Rules, EDR Exclusions and Blocked Hashes managed in ESET PROTECT
•Version 3.0 and later—Supports Indicators in Advanced Search and Incident correlation
ESET Inspect Connector is updated automatically. Verify that all managed devices run a supported version and update manually the devices where the automatic update could not be applied. Endpoints with an unsupported version lose EDR/XDR functionality after the ESET Inspect console is terminated and report operational issues until they are updated.
Frequently asked questions
Is this the End of Life of ESET Inspect?
No. Only the ESET Inspect console is terminated. The EDR/XDR capabilities and ESET Inspect Connector remain available through ESET PROTECT.
Does the consolidation affect ESET Inspect On-Prem?
No. ESET Inspect On-Prem is a standalone product. The consolidation applies only to the cloud version.
Will I lose EDR/XDR functionality after the ESET Inspect console is terminated?
No. The core detection and response functionality is available in ESET PROTECT. Some features are redesigned, and a small subset of features is deprecated (see Deprecated features).
Will my data be migrated to ESET PROTECT?
Most data and configurations are available in ESET PROTECT. Some data types cannot be migrated because of architectural changes (see Data that is not migrated).
What do I need to do?
If you use the EDR Detection API or the Syslog export of ESET Inspect alerts, plan the migration to the Indicator-based replacements when they become available. Familiarize yourself with the detection and response workflows in ESET PROTECT. Everything else is performed automatically.
What happens if I continue using an earlier ESET Inspect Connector version?
Earlier versions do not support Indicators, Incident correlation, EDR Rules, EDR Exclusions and Blocked Hashes in ESET PROTECT. After the ESET Inspect console is terminated, such devices do not provide full EDR/XDR functionality. Update them as soon as possible.
When will my environment be migrated?
New customers are onboarded directly into ESET PROTECT. Existing customers follow later, depending on whether they actively use the ESET Inspect console and whether they rely on the EDR Detection API or the Syslog export. Active console users are notified in the product 60 days before their console is terminated.
Find more about consolidating ESET Inspect and ESET PROTECT (Open XDR).