Problem/Symptom: Alerts do not appear in the Attack Log page or on dashboards after upgrading the Manager.
Potential Cause and Remedy: If the alerts are missing in the Attack Log page, or you see a blank dashboard after upgrading the Manager, you need to run the Apache Solr scripts which ensures the previous alerts and other events are displayed in the Manager GUI. For more information on the alerts processing scripts and Apache Solr scripts, refer to the section Run the Apache Solr scripts in the Trellix Intrusion Prevention System Installation Guide.
Note
For detailed information on synchronizing IPS alerts in the Solr Database in Manager version 9.1.7.77 till 10.1.7.40, refer to KB86158.
From software version 10.1.7.44 or above, the Manager should automatically import the Solr data. If the alerts are missing from the Attack Log or on Manager dashboards after the installation, it indicates that the automatic import of Solr data has not been successful. In such a case, a critical fault is displayed in the Manager → <Admin Domain Name> → Troubleshooting → Logs → Faults to notify you regarding the failure in import of Solr data.
You need to run SolrDB import manually in the Manager to troubleshoot this issue. To do so, perform the following steps.
For Windows-based Manager:
Steps:
Stop the Manager Service and Manager Watchdog Service.
Navigate to
<Manager_Install_dir>\Solr\server\solr\alertsand take a backup of the data folder. Keep this folder outside the Manager installation folder.Delete the data folder present in
<Manager_Install_dir>\Solr\server\solr\alerts.Set the Database flag to initiate import using the following SQL query:
UPDATE iv_emsproperties SET VALUE="true" WHERE NAME="iv.core.solr.importenabled";
Now, start the Manager Service and Manager Watchdog Service.
Wait till the Manager GUI is up and running. Then, check for the alerts in Attack Log and information on Manager dashboards.
For Linux-based Manager (Trellix OS):
<listitem>The following table lists the impact of alert data migration in Manager/Central Manager:
Component | Impact | Alert data storage | Note |
|---|---|---|---|
Manager | Disk is wiped | Alerts are stored in MariaDB and Solr. The Attack Log will have no alerts immediately after migration. | Alert data gets restored on the Manager startup. Expect a delay before the alerts appear in the Attack Log. To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status. |
Central Manager | Disk is wiped; Solr files are deleted. | Alerts are not stored in the database. Consequently, the Central Manager will have no alerts immediately after migration. | Alert restoration starts with synchronization from the Manager. Expect a delay before the alerts appear in the Attack Log. |
For any assistance, contact Trellix support.
For Linux-based manager (MLOS):
Steps:
Stop the Manager service using
manager stopcommand.Stop the Manager Watchdog service using
watchdog stopcommand.Login to the Manager via SFTP window.
Navigate to the directory
/opt/IPSManager/Solr/server/solr/alerts. Locate the data folder insideopt/IPSManager/Solr/server/solr/alertsdirectory and take a backup of that folder by copying it to the local machine.Note
If you are using Manager version 10.1.7.44 - 10.1.7.61, the directory path would be
/opt/NetworkSecurityManager/Solr/server/alerts.After the backup has been taken, delete the data folder inside the
/opt/IPSManager/Solr/server/solr/alertsdirectory.Open a terminal and run the
dbshellcommand. Enter the DB username and password, when prompted.Set the database flag to initiate import using the following SQL query:
UPDATE iv_emsproperties SET VALUE="true" WHERE NAME="iv.core.solr.importenabled";
Start the Manager service using
manager startcommand.Start the Manager Watchdog service using
watchdog startcommand.Wait till the Manager GUI is up and running. Then, check for the alerts in Attack Log and information on Manager dashboards.