The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Backup and restore best practices

Prev Next

Note the following suggestions for successful backup and restore of Trellix IPS data:

  • Protect your backups from tampering by creating a digital fingerprint of the file using a hash function such as MD5 or SHA-1.

  • Back up your configuration data after major changes, such as created admin domains, Sensor addition, port configuration, and policy additions/modifications.

  • The All Tables and Audit Tables options can be rather large in size, depending upon the amount of alert data in your database. Trellix recommends saving these types of backups to an alternate location, preferably an alternate system.

  • When scheduling backups, set a unique time when no other scheduled functions (archivals, database tuning) are running. The time should be a minimum of an hour after/before other scheduled actions.

  • When restoring your data, note that all related table information in the database is overwritten. For example, restoring a Config Tables backup overwrites all current information in the configuration table of the database. Thus, any changes not backed up are erased in favor of the restored backup.

  • While a MariaDB backup is performed, the tables being backed up are placed in a READ LOCAL LOCK state. New records can be inserted in these tables while the backup is in progress, although these new records will not show up in the backup. However updates/modifications of existing records are not allowed during the backup. While a backup is in progress, you will not be able to perform the following activities:

    • Modify the configuration

    • Acknowledge and delete alerts

    • Acknowledge and delete faults

    • Add audit log entries

    • Purge the alert and packet logs

    • Perform database tuning.

  • New alerts and packet logs will continue to be added to the database during the backup.

  • In case of problems during database backup or restore, try after you complete the following tasks:

    • Exclude the following MariaDB directories from anti-virus scanning:

      • data

      • innodbdata

    • Create a new directory like c:\mariadbtmp, which will act as temporary directory for database. If the system has multiple physical disks, then Trellix recommends that you create this directory on a drive different than where Trellix IPS and MariaDB are installed to spread the load effectively.

    • Include the following entry in the %programfiles%\Trellix\IPS Manager\MariaDB\my.ini file under [mariadbd] section: tmpdir=c:/mariadbtmp

    • Restart both Trellix IPS and MariaDB services.