[KB8968] Infrastructure updates required for incident correlation backend for ESET's XDR migration

Issue

Solution

We are migrating the Incident correlation backend for ESET's XDR to a new, state-of-the-art detection platform. The migration is already underway for eligible customers. No action is required on your side for the migration itself.

However, based on the records, part or all of your environment does not currently meet the eligibility criteria for the new platform. To ensure your organization benefits fully from the migration, you need to update your infrastructure by the end of July 2026.


Timeline

Migration for eligible customers is currently in progress. Other migration waves will continue from August 17, 2026, onwards without prior notice. The aim is to complete the migration by the end of September 2026.

Contact us if you need more information, assistance with the update, or additional time before the migration.


Eligibility criteria

To be included in the new Incident correlation backend for ESET's XDR:

  • Update the ESET Inspect Connector and ESET Management Agent to the latest versions on all devices
  • Verify that connectivity to our XDR environment is allowed in your network configuration (not blocked by firewall or network policy)

In line with ESET future product plans, the latest versions will eventually be required to maintain protection on the endpoint devices themselves. A dedicated follow-up communication with details and timelines will be sent separately. Updating now and enabling auto-updates ensures you stay ahead of this requirement.


Migration benefits

  • Significantly improved threat detection at the core of the platform
  • Cross-perimeter detection capability – correlation of signals across your entire environment, not just from endpoints
  • Better stability, performance, and reliability

Risk of a partially updated environment

Incident correlation is the core detection workflow of ESET's XDR. Individual detections across your environment are automatically correlated into Incidents in ESET PROTECT, giving you a complete picture of an attack.

If only a portion of your infrastructure is eligible:

  • Devices that are updated and connected will continue to be correlated into Incidents
  • Devices that are not updated will be excluded from Incident correlation
  • Devices that are not updated may also have limited or no MDR/MDR Ultimate monitoring coverage, reducing the ability of ESET analysts to detect, investigate, and respond to suspicious activity on those endpoints

This creates blind spots in your environment. Activity on excluded devices will not contribute to Incidents, and you risk missing a security incident that would otherwise have been detected through correlation.

Additionally, incomplete endpoint coverage can reduce the effectiveness of your MDR or MDR Ultimate service by limiting visibility into parts of your environment, preventing comprehensive monitoring and investigation across all devices.


Protection status

Your devices remain protected. Devices that are not updated remain fully protected by both ESET endpoint protection and ESET Endpoint Detection and Response on a per-device basis. They will simply no longer participate in Incident correlation, which is the main workflow of the platform.