The Archive Now action enables you to archive alerts and packet logs on demand into an archival file for future restoration. This process reads alerts and packet logs for the given time range from the database and writes them into a zip file.
Note
Archive your alerts and packet logs regularly. We recommend that you archive your alert data monthly, and that you discard alert and packet log information from your database every 90 days to manage your database size. There is a 1 GB size limitation for restoration (import of the file in the Manager) of a single archive file. However, you can extract an archive zip file greater than 4 GB in size but in that case the archived file cannot be restored.
Archived files less than 4GB in size are saved locally to the Manager, and can be exported to your client.
Steps:
Select Manager → <Admin Domain Name> → Maintenance → Data Archiving → IPS → Archive Now
The Archive Now page is displayed.
Archive Now page.png)
Choose one of the following time spans in Time Range:
A single day (yyyy/mm/dd) — Select alerts and packet logs for a single day in the format yyyy/mm/dd. Default is the Manager system date.
Within a specific period (yyyy/mm/dd hh:mm:ss) — Select alerts and packet logs between the begin and end dates in the format yyyy/mm/dd hh:mm:ss. Default Begin Date is the oldest alert detected time and default End Date is the Manager system time.
In the past — Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (default), or hours. Select a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is the Manager system time).
Click Start.
When the archival process is complete, the file is saved to
<Manager_Install_Dir>\alertarchivalNote
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.The files also appear in the Restore Archives page, where you can view details of the archived files.
.png)
Optionally, select an archived file in the Export Archives page and click Export to download that file from the Manager to your client.
Note
You can import an exported file into another Manager, such as a test Manager.