The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Backup of data and configurations

Prev Next

For the back up of Trellix IPS data and configurations, following best practices are recommended:

  • Back up Manager data either within the Manager server (%programfiles%\Trellix\IPS Manager\App\Backups folder) or preferably on any external media.

  • Back up all information, including configurations, alerts, and audits.

  • Implement a schedule for backups using the Backup scheduler. Backing up config tables weekly is recommended. (Be sure to schedule this at a time when other processes will not be running concurrently.)

  • As the All Tables and Event Tables options can be rather large in size (depending upon the amount of alert data in the database) these types of backups should be saved off the Manager server.

  • Saving the All Tables settings on a monthly basis is strongly recommended.

  • Protect backups from tampering by creating a digital fingerprint of the file using a hash function such as MD5 or SHA-1.

  • Test restoration of backups periodically to ensure that a backup was successful and valid. The best way to do this is to perform a "test" restore of the backup on a secondary, non-production Manager.

  • The Config Tables option backs up only tabled information relating to configured tasks. This option is enabled by default to occur every Sunday night. This is set within the Backup Scheduler action.

  • Save actual configurations of Sensors (not just the config tables) using the Export option under the Sensor_Name tab. This creates an XML file (no attempt to read this file should be made) that can be imported to any Sensor of the same type in the future. Save actual Sensor configurations once a week.