The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerts do not show up in Attack Log or on dashboards after upgrading the Manager

Prev Next

Problem/Symptom: Alerts do not appear in the Attack Log page or on dashboards after upgrading the Manager.

Potential Cause and Remedy: If the alerts are missing in the Attack Log page, or you see a blank dashboard after upgrading the Manager, you need to run the Apache Solr scripts which ensures the previous alerts and other events are displayed in the Manager GUI. For more information on the alerts processing scripts and Apache Solr scripts, refer to the section Run the Apache Solr scripts in the Trellix Intrusion Prevention System Installation Guide.

Note

For detailed information on synchronizing IPS alerts in the Solr Database in Manager version 9.1.7.77 till 10.1.7.40, refer to KB86158.

From software version 10.1.7.44 or above, the Manager should automatically import the Solr data. If the alerts are missing from the Attack Log or on Manager dashboards after the installation, it indicates that the automatic import of Solr data has not been successful. In such a case, a critical fault is displayed in the Manager → <Admin Domain Name> → Troubleshooting → Logs → Faults to notify you regarding the failure in import of Solr data.

You need to run SolrDB import manually in the Manager to troubleshoot this issue. To do so, perform the following steps.

For Windows-based Manager:

Steps:

  1. Stop the Manager Service and Manager Watchdog Service.

  2. Navigate to <Manager_Install_dir>\Solr\server\solr\alerts and take a backup of the data folder. Keep this folder outside the Manager installation folder.

  3. Delete the data folder present in <Manager_Install_dir>\Solr\server\solr\alerts.

  4. Set the Database flag to initiate import using the following SQL query:

    UPDATE iv_emsproperties SET VALUE="true" WHERE NAME="iv.core.solr.importenabled";
  5. Now, start the Manager Service and Manager Watchdog Service.

  6. Wait till the Manager GUI is up and running. Then, check for the alerts in Attack Log and information on Manager dashboards.

For Linux-based Manager (Trellix OS):

<listitem>

The following table lists the impact of alert data migration in Manager/Central Manager:

Component

Impact

Alert data storage

Note

Manager

Disk is wiped

Alerts are stored in MariaDB and Solr.

The Attack Log will have no alerts immediately after migration.

Alert data gets restored on the Manager startup.

Expect a delay before the alerts appear in the Attack Log.

To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status.

Central Manager

Disk is wiped; Solr files are deleted.

Alerts are not stored in the database.

Consequently, the Central Manager will have no alerts immediately after migration.

Alert restoration starts with synchronization from the Manager.

Expect a delay before the alerts appear in the Attack Log.

</listitem>

For any assistance, contact Trellix support.

For Linux-based manager (MLOS):

Steps:

  1. Stop the Manager service using manager stop command.

  2. Stop the Manager Watchdog service using watchdog stop command.

  3. Login to the Manager via SFTP window.

  4. Navigate to the directory /opt/IPSManager/Solr/server/solr/alerts. Locate the data folder inside opt/IPSManager/Solr/server/solr/alerts directory and take a backup of that folder by copying it to the local machine.

    Note

    If you are using Manager version 10.1.7.44 - 10.1.7.61, the directory path would be /opt/NetworkSecurityManager/Solr/server/alerts.

  5. After the backup has been taken, delete the data folder inside the/opt/IPSManager/Solr/server/solr/alerts directory.

  6. Open a terminal and run the dbshell command. Enter the DB username and password, when prompted.

  7. Set the database flag to initiate import using the following SQL query:

    UPDATE iv_emsproperties SET VALUE="true" WHERE NAME="iv.core.solr.importenabled";
  8. Start the Manager service using manager start command.

  9. Start the Manager Watchdog service using watchdog start command.

  10. Wait till the Manager GUI is up and running. Then, check for the alerts in Attack Log and information on Manager dashboards.