You can archive alerts and packet logs from either the Trellix IPS user interface or from the standalone database admin tool. However, you can avoid the additional workload on Manager server by using the database admin tool. The archived data is stored in a .zip file at %programfiles%\Trellix\IPS Manager\App\alertarchival. Note that data from the following tables are archived:
- iv_alert
- iv_alert_data
- iv_packetlog
Note the following before attempting to archive alerts:
- You can restore alerts only if the major versions of the backed up Manager and the present Manager match. For example, a backup from Manager 9.1.5.7 can be restored on a Manager version 9.2.3.11 or 9.2.5.6. A backup from Manager 9.2.9.8 cannot be restored on 10.1.7.4.
- You cannot restore alerts of a later version of the Manager on an earlier version of the Manager. For example, you cannot back up alerts from Manager version 10.1.7.4 and restore it on Manager version 9.2.9.8.
Task
- Navigate to %programfiles%\Trellix\IPS Manager\App\bin.
- Execute the dbadmin.bat file. The standalone tool opens.
-
Select
Archival → Alert Archival.
Database Admin Tools - Alert Archival Settings .png)
- Specify the time period of the data to be archived either by using the Day Picker or by specifying the start date and time and the end date and time.
-
Click
Archive. Archive Confirmation dialog pop-up appears. Click
Yes.
When the process is complete, the archived file is saved to %programfiles%\Trellix\IPS Manager\App\alertarchival. This file will also be listed in a table when you restore files using this tool or Manager.