An alternative to using the Alert Pruning action for alert and packet log deletion is to delete these files using purge.bat. To do this, perform the following steps:
Stop the Manager service.
Follow one of these methods to stop the Manager service:
Right-click on the Manager icon at the bottom-right corner of your server and stop the service.
Select Windows Control Panel → Administrative Tools → Services. Then right-click on Trellix IPS Manager and select Stop.
Do one of the following:
Open your Trellix IPS installation folder and run
purge.batfrom<Manager_Install_Dir>\bin\purge.batNote
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.Open a DOS prompt and type
<Manager_Install_Dir>\bin\purge.bat
Note
Purge.bat also has the option to remove records flagged for deletion. This can significantly increase the amount of time it takes to finish, depending on the size of the database.
Answer the following questions:
Is the Manager Down or Off-Line (Y/N)?
Note
The Manager service must be disabled prior to using purge.bat. If the service is not disabled, the purge will not continue.
Do You Wish To Perform DB Tuning After The Purge Operation (Y/N)?
Tip
You can perform DB tuning separately from the purge operation.
Alert and packet log data alert
Enter the Number of days of Alerts and Packet Log data to be preserved. For example, to delete alerts/packet logs older than 90 days, type 90.
Enter the Number of Alerts to be preserved.
You Are About To Delete Alerts And PacketLog Data Older Than X Days. Type Y to continue.
Do You Wish To Purge Alerts / Packet Logs That Have Been 'Marked For Delete' Through The Attack Manager? Type Y to continue
Host event data
Number of days of Host Event data to be preserved
Number of Host Entries to be preserved
You Are About To Delete Host Event Data Older Than X Days. Type Y to continue.
If The Number of Remaining Hosts Is Still More Than XXX, Deletion Will Be Continued Until It Reaches XXX. Type Y to continue.
Do You Wish To Purge Performance Monitoring Data [Y/N]. Type Y to continue.
Sensor performance data
Number of days of Raw performance data to be preserved
Number of days of Hourly performance data to be preserved
Number of days of Daily performance data to be preserved
Number of weeks of weekly performance data to be preserved
Number of months of monthly performance data to be preserved
You Are About To Delete Raw Performance Data Older Than X Days, Hourly Data Older than X Days, Daily Data Older than X Days, Weekly Data Older Than X Weeks, Monthly Data Older Than X Months. Are you sure you want to proceed (Y/N): Type Y to delete.
Application Visualization data
Number of days of Raw Application Visualization data to be preserved
Number of days of Hourly Application Visualization data to be preserved
Number of days of Daily Application Visualization data to be preserved
Number of weeks of weekly Application Visualization data to be preserved
Number of months of monthly Application Visualization data to be preserved
You Are About To Delete Raw Application Visualization Data Older Than X Days, Hourly Data Older than X Days, Daily Data Older than X Days, Weekly Data Older Than X Weeks, Monthly Data Older Than X Months. Are you sure you want to proceed (Y/N): Type Y to delete.
Restart the Manager service after completion.