You can archive alerts and packet logs from either the Trellix IPS user interface or from the standalone database admin tool. However, you can avoid the additional workload on Manager server by using the database admin tool. The archived data is stored in a .zip file at %programfiles%\Trellix\IPS Manager\App\alertarchival. Note that data from the following tables are archived:
iv_alert
iv_alert_data
iv_packetlog
Note the following before attempting to archive alerts:
You can restore alerts only if the major versions of the backed up Manager and the present Manager match. For example, a backup from any 10.1 Manager version can be restored on any other 10.1 Manager version. A backup from a 10.1 Manager cannot be restored on a 11.1 Manager.
You cannot restore alerts of a later version of the Manager on an earlier version of the Manager. For example, you cannot back up alerts from Manager version 10.1.7.65 and restore it on Manager version 10.1.7.50.
To archive alerts and packet logs using the standalone Database admin tool:
Steps:
Navigate to
%programfiles%\Trellix\IPS Manager\App\bin.Execute the dbadmin.bat file. The standalone tool opens.
Select Archival → Alert Archival.
Database Admin Tools - Alert Archival Settings.jpg)
Specify the time period of the data to be archived either by using the Day Picker or by specifying the start date and time and the end date and time.
Click Archive. Archive Confirmation dialog pop-up appears. Click Yes.
When the process is complete, the archived file is saved to
%programfiles%\Trellix\IPS Manager\App\alertarchival. This file will also be listed in a table when you restore files using this tool or Manager.