Over time, a relational database can experience performance issues if the data is not re-tuned on a recurring basis. By regularly diagnosing, repairing, and tuning your database internals, you can ensure optimal database performance. Trellix provides a set of Manager interface options (Manager → <Admin Domain Name> → Maintenance → Database Tuning) and a standalone utility, called dbadmin.bat, to maintain database performance.
Note
You can also use dbtuning.bat to tune your Trellix IPS database. However, Trellix strongly encourages you to use dbadmin.bat for all your database administration tasks.
The database tuning feature does the following:
- Defragments tables where rows/columns are split or have been deleted
- Re-sorts indexes
- Updates index statistics
- Computes query optimizer statistics
- Checks and repairs tables
On a regular basis (minimum recommendation: one month), perform database tuning on your Manager server. Completion time is dependent on the number of alerts/packet logs in the database and the performance of your Manager server's physical hardware platform.
Note
When you perform off-line database tuning, you must shut down the Manager service for proper performance. Trellix recommends scheduling this downtime for whenever you plan to re-tune the database. Your Sensor can continue to operate and generate alerts because of built-in alert buffers.