The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Delete alerts and packet logs from the database using purge.bat

Prev Next

An alternative to using the Alert Pruning action for alert and packet log deletion is to delete these files using purge.bat. To do this, perform the following steps:

  1. Stop the Manager service.

    Follow one of these methods to stop the Manager service:

    • Right-click on the Manager icon at the bottom-right corner of your server and stop the service.

    • Select Windows Control Panel → Administrative Tools → Services. Then right-click on Trellix IPS Manager and select Stop.

  2. Do one of the following:

    • Open your Trellix IPS installation folder and run purge.bat from<Manager_Install_Dir>\bin\purge.bat

      Note

      The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

    • Open a DOS prompt and type <Manager_Install_Dir>\bin\purge.bat

    Note

    Purge.bat also has the option to remove records flagged for deletion. This can significantly increase the amount of time it takes to finish, depending on the size of the database.

  3. Answer the following questions:

    1. Is the Manager Down or Off-Line (Y/N)?

      Note

      The Manager service must be disabled prior to using purge.bat. If the service is not disabled, the purge will not continue.

    2. Do You Wish To Perform DB Tuning After The Purge Operation (Y/N)?

      Tip

      You can perform DB tuning separately from the purge operation.

    Alert and packet log data alert

    1. Enter the Number of days of Alerts and Packet Log data to be preserved. For example, to delete alerts/packet logs older than 90 days, type 90.

    2. Enter the Number of Alerts to be preserved.

    3. You Are About To Delete Alerts And PacketLog Data Older Than X Days. Type Y to continue.

    4. Do You Wish To Purge Alerts / Packet Logs That Have Been 'Marked For Delete' Through The Attack Manager? Type Y to continue

    Host event data

    1. Number of days of Host Event data to be preserved

    2. Number of Host Entries to be preserved

    3. You Are About To Delete Host Event Data Older Than X Days. Type Y to continue.

    4. If The Number of Remaining Hosts Is Still More Than XXX, Deletion Will Be Continued Until It Reaches XXX. Type Y to continue.

    5. Do You Wish To Purge Performance Monitoring Data [Y/N]. Type Y to continue.

    Sensor performance data

    1. Number of days of Raw performance data to be preserved

    2. Number of days of Hourly performance data to be preserved

    3. Number of days of Daily performance data to be preserved

    4. Number of weeks of weekly performance data to be preserved

    5. Number of months of monthly performance data to be preserved

    6. You Are About To Delete Raw Performance Data Older Than X Days, Hourly Data Older than X Days, Daily Data Older than X Days, Weekly Data Older Than X Weeks, Monthly Data Older Than X Months. Are you sure you want to proceed (Y/N): Type Y to delete.

    Application Visualization data

    1. Number of days of Raw Application Visualization data to be preserved

    2. Number of days of Hourly Application Visualization data to be preserved

    3. Number of days of Daily Application Visualization data to be preserved

    4. Number of weeks of weekly Application Visualization data to be preserved

    5. Number of months of monthly Application Visualization data to be preserved

    6. You Are About To Delete Raw Application Visualization Data Older Than X Days, Hourly Data Older than X Days, Daily Data Older than X Days, Weekly Data Older Than X Weeks, Monthly Data Older Than X Months. Are you sure you want to proceed (Y/N): Type Y to delete.

    1. Restart the Manager service after completion.