The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Database maintenance and tuning

Prev Next

Once you have determined the necessary database capacity for archiving your alerts and packet logs, as well as other Trellix IPS generated logs and files, you should consider a maintenance plan that keeps your database performing at an optimal level. Deleting old, unwanted alerts, packet log entries, and other files (for example, backups, saved reports) ensures adequate capacity for future data.

For database maintenance, Trellix IPS offers two solutions:

  • File pruning action (Manager → <Admin Domain Name> → Maintenance → Database Pruning → File and Database Pruning) enables you to set a schedule by which Trellix IPS generated logs and files are deleted from Trellix IPS (Manager) and database. File pruning allows you to delete Trellix IPS data that has reached a set age (number of days old). Data is deleted according to a weekly schedule; this time, seen as Enable File and Database Pruning?, Recur every, and Start Time (24-hour clock), must be enabled to operate.

    If you plan to use Alert Pruning (Manager → <Admin Domain Name> → Maintenance → Database Pruning → Alert Pruning) to delete alert and packet log data, Trellix recommends entering a value — such as 90, as in 90 days — in the Maximum Alert Age for Report Data field. This allows for long-term analysis of alerts and packet logs without overburdening your database with millions of records, which may affect long-term and overall database performance. By setting the value to 90 days, all alerts and packet logs older than 90 days are deleted at the scheduled time every day.

    Suppose you set a value of 90 days for the Maximum Alert Age for Report Data field and a value of 10000 for the Maximum Alerts to Store in Solr Database (Dashboard Data) field. Then at the scheduled time, Manager deletes all alerts that are older than 90 days and then checks if the number of alerts and packet logs is less than or equal to 10000. If it is more than 10000, it deletes the oldest alerts and packet logs until the number is less than or equal to 10000.

    You can also delete alerts in the Attack Log. This, however, only marks alerts for deletion in the database. To permanently delete these alerts from the database, you need to use the DB Purge feature in the dbadmin.bat utility or the purge.bat utility. Scheduled alert and packet log purge as part of Alert Pruning (Manager → <Admin Domain Name> → Maintenance → Database Pruning → Alert Pruning) has no effect on the alerts marked for deletion. Deleting alerts marked for deletion is a time-consuming process. Therefore, to delete alerts marked for deletion that are less than the age specified in the Maximum Alert Age for Report Data field, you need to use the dbadmin.bat or the purge.bat utility and manually delete these alerts. Also, note that the Manager has to be stopped to run the dbadmin.bat.

    Note

    Entering a very large value (such as 500, as in 500 days) is not recommended due to the capacity required to archive 500 days worth of alerts. Your requirements will determine the number of days you need to maintain alerts. If you must keep alerts for several hundred days, ensure that you have the necessary hard drive space on your Manager server, or back up your alert tables regularly.

Tip

You can use the purge.bat utility or the dbadmin.bat utility for alert and packet log data maintenance. Thus, if possible, do not schedule disk space maintenance with respect to alert and packet logs.

  • Purge.bat utility: Provided with your Manager installation is the alert and packet log data maintenance utility named purge.bat (%programfiles%\Trellix\IPS Manager\App\bin\purge.bat). This utility enables on-demand deletion of alerts and packet log data from your database. Alerts and packet logs can be deleted that are older than a specified number of days. Using purge.bat, you can automatically start the database tuning utility, dbtuning.bat, immediately after the purge is completed. This utility ensures your database is properly maintained for optimal continued use.