The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert action synchronization between Managers

Prev Next

The actions that are triggered on these generated alerts from the active Manager are synchronized with the standby Manager in real time.

The following table explains the possible scenarios that can be observed during MDR alert action synchronization.

Scenario

MDR alert action synchronization

No Communication between MDR Managers.

Alert actions from active manager fails to synchronize to the standby Manager in real time. These actions are saved in the database and cache, and will be synchronized to the standby Manager as soon as the connection is back.

Standby Manager is down.

Alert actions from active Manager fails to synchronize to the standby Manager in real time. These actions are saved in the database and cache, and will be synchronized to the standby Manager as soon as the connection is back.

Active Manager goes down comes back as standby.

Any alert actions done in the new active manager will be synchronized to the new standby Manager.

MDR is suspended.

Alert actions are not synchronized when the MDR is in suspended mode. These actions are saved in the database and cache, and synced when MDR is resumed.

Note

Alert synchronization between the peer Managers restores the missed alerts and packet logs from previous 24 hours. The maximum number of events restored with synchronization is 10,000.