You can back up Trellix IPS data using either the Manager server or the standalone Database Admin tool. However, you can avoid the additional workload on the Manager server by using the tool.
Note the following before attempting to backup data:
You can restore Config Tables or All Tables only if the major versions of the backed up Manager and the present Manager match. For example, a backup from any 10.1 Manager can be restored on any other 10.1 Manager and not on 11.1 Manager.
You cannot restore Config Tables or All Tables of a later version of the Manager on an earlier version of the Manager. For example, you cannot back up the Config Tables from Manager version 10.1.7.65 and restore it on Manager version 10.1.7.50.
To backup using the standalone Database Admin tool:
Steps:
Stop the Manager service.
You can stop the Manager service by any of the following methods:
Right-click on the Manager icon at the bottom-right corner of your Windows server and stop the service.
Select Windows Control Panel → Administrative Tools → Services and right-click on Trellix IPS Manager and select Stop.
Navigate to
<Manager_Install_Dir>\bin.Note
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\AppExecute the dbadmin.bat file.
The standalone tool opens.
Note
You can also use dbbackup.bat to back up and restore data. However, you will be directed to use dbadmin.bat for all your database administration tasks.
Database Admin Tools - DB Backup Tab.jpg)
Select one of the following backup Type choices from the drop down:
All Tables— The entire Manager database consisting of configuration, user activity, event and trend tables.
Config Tables— Information regarding Manager configuration.
Audit Tables— Information regarding user activity.
Event Tables— Information regarding events such as, alerts, packetlogs, hosts and Sensor performance.
Trend Tables— Trend patterns (daily/weekly/monthly) of alerts and Sensor performance events.
Caution
Backup of Event table and All table option can be large in size depending upon the amount of event data (i.e. alert/ host/ Sensor performance metrics data) in your database.
Type a backup Filename. You can use alphanumeric characters including hyphens and underscores (for example, backup_01-10-03).
Optionally type the backup Directory where you want the backup to be stored.
If you do not specify a backup directory, then the backup is stored in the default backup directory at
<Manager_Install_Dir>\Backups. It creates a new directory under<Manager_Install_Dir>if the Backups directory does not already exist.Optionally type a description of your backup in Comments.
Click Backup. After a few moments, the following message appears: "Database backup successful."
You can see the backup information by clicking the DB Restore tab. In the backup directory, you will find an XML file (JAR format) and the other with the file extension .dmp with the backup file name that you specified.
Back up the .jar and .dmp files to a safe location.