Over time, a relational database can experience performance issues if the data is not re-tuned on a recurring basis. By regularly diagnosing, repairing, and tuning your database internals, you can ensure optimal database performance. Trellix provides a set of Manager interface options (Manager → <Admin Domain Name> → Maintenance → Database Tuning) and a standalone utility, called dbadmin.bat, to maintain database performance.
Note
You can also use dbtuning.bat to tune your Trellix IPS database. However, Trellix strongly encourages you to use dbadmin.bat for all your database administration tasks.
The database tuning feature does the following:
Defragments tables where rows/columns are split or have been deleted
Re-sorts indexes
Updates index statistics
Computes query optimizer statistics
Checks and repairs tables
On a regular basis (minimum recommendation: one month), perform database tuning on your Manager server. Completion time is dependent on the number of alerts/packet logs in the database and the performance of your Manager server's physical hardware platform.
From 11.1 Update 5 release onwards, IPS Manager performs tuning of iv_packetlog table along with other data tables when the DB tuning operation is initiated or scheduled from the Manager UI. You can use Manager → <Admin Domain Name> → Maintenance → Database Tuning page to tune this table on-demand or enable its automated tuning.
If the iv_packetlog table file size exceeds 100 GB, the Manager skips the tuning of that database table to maintain normal operations and a warning fault Packetlogs table tuning skipped is raised. In such cases, you should perform a one-time offline tuning of the database using dbadmin.bat or dbtuning.bat utility which will also tune the iv_packetlog table. The one-time offline database tuning operation reduces the table size and enables you to initiate or schedule the tuning of this table next time from the Manager UI. To learn more about the fault, refer to the section Manager warning faults.
Note
If you are using any Manager version prior to 11.1 Update 5 release, you need to manually perform the weekly offline database tuning using dbadmin.bat or dbtuning.bat to tune iv_packetlog table. The offline tuning of the database can be performed irrespective of the table size. For more information on tuning the database using dbadmin.bat, refer to Using the database admin tool and Tune your database using dbadmin.bat.
When you perform offline database tuning, you must shut down the Manager service for proper performance. Trellix recommends scheduling this downtime for whenever you plan to re-tune the database. Your Sensor can continue to operate and generate alerts because of built-in alert buffers.
Tip
When data tuning gets triggered while the alert pruning operation is in progress, data tuning waits for permission and resumes after alert pruning is complete. Similarly, when alert pruning gets triggered while the data tuning operation is in progress, alert pruning waits for permission and resumes after data tuning is complete. This enhancement prevents overlapping and failure scenarios of data tuning and alert pruning.