The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert Pruning

Prev Next

The Alert Pruning option enables you to manage the database space required for the alerts generated by your Trellix IPS Sensors. Alert pruning is an important, ongoing task that must be performed for optimal Manager and database performance. If your database were to grow unchecked with millions of stored alerts, analysis using the Attack Log page or Reports would slowdown considerably.

The Manager uses database which has a pre-defined alert capacity of 10,000,000 alerts. This means Manager will generate system fault messages when your database is nearing or exceeding the 10,000,000 limit by issuing warnings at 80-90%, 90-95%, 95-100%, >100% interval ranges. This value is purely for capacity planning and not an actual constraining limit on your database. You can customize this limit to properly manage your capacity needs.

In addition, the Manager uses an open-source search application called Solr, which stores alerts within a flat file. The alert capacity correlates directly with the amount of memory installed in the Manager server. If you have the minimum memory of 16GB, Solr supports up to 10 million alerts. If you have memory of 32 GB or higher, Solr supports up to 20 million alerts.

Note

Trellix recommends that you delete items, such as alerts and other system-generated files, at scheduled intervals to create more disk space.

Alert Pruning page
Alert Pruning page


To plan Manager database capacity, do the following:

Steps:

  1. Select Manager → <Admin Domain Name> → Maintenance → Database Pruning → Alert Pruning.

    • Enable Alert Pruning: Select Yes to delete all alerts and packet logs in the database that are older than the number of days set in Maximum Alert Age for Report Data.

      For Alert & Packet Log Data, Trellix strongly recommends entering a large value (such as 90, as 90 days is the default) in Maximum Alert Age for Report Data. You may want to perform long-term analysis using the information in your database, and having alerts and packet logs deleted, for example, every 10 days would be detrimental.

      Note

      • The scheduled maintenance deletes all alerts older than the value entered in the Retain Alerts by Max number of days field or exceeding the alert count specified in the Max Alert Quantity field. This helps you automate database cleaning based on the alert threshold count.

      • If after deleting alert and packet log by number of days, the number of alerts are still more than the set threshold value, Manager starts deleting all old alerts till the alert count falls below the Max Alert Quantity value.

    • Set the time (Pruning Start Time: At Hour and Minutes) for the selected day when you want scheduled maintenance to occur.

  2. Type a number greater than or equal to 10,000 in Maximum Alerts to Store in Solr Database (Dashboard Data).

    Note

    You must set this value depending on the amount of memory in your Manager server. If you have the minimum memory of 16GB, Solr supports up to 10 million alerts. If you have memory of 32 GB or higher, Solr supports up to 20 million alerts.

  3. Do one of the following for Maximum Alerts to Store in Manager Database (Report Data):

    • To allocate more disk space for your calculations, type a number greater than 10,000,000 (ten million).

    • To allocate less disk space for your calculations, type a number less than 10,000,000.

    • To calculate disk space capacity, click Calculate. This calculator has specific fields related to determining the database allocation space required to maintain your alerts and packet logs.

    Do the following in Calculate Maximum Alert Quantity window.

    1. Type the gigabytes allocated to the database at Desired Disk Space Allocation.

    2. (Optional) Type an approximate size for each packet log in your database (at Approx Packet Log Size).

    3. Enter Maximum Alert Quantity.

    4. Click Calculate. The number of alerts your database can maintain is listed in the # of Alerts field.

    5. (Optional) Click Clear to start a new calculation.

      Calculate Maximum Alert Quantity dialog
      Calculate Maximum Alert Quantity dialog


  4. Type the age of the alerts that can be deleted (Maximum Alert Age for Report Data).

  5. Do one of the following:

    • Click Save to save your changes.

    • Click GUID-DE8F9231-1BB5-42A7-B78B-1FDD431543A8-low.png to revert back to the previously saved values, thus aborting any current changes.

Tip

When data tuning gets triggered while the alert pruning operation is in progress, data tuning waits for permission and resumes after alert pruning is complete. Similarly, when alert pruning gets triggered while the data tuning operation is in progress, alert pruning waits for permission and resumes after data tuning is complete. This enhancement prevents overlapping and failure scenarios of data tuning and alert pruning.