The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Delete unwanted data using dbadmin.bat

Prev Next

You can delete any redundant data including alerts and packet logs from your Trellix IPS database using the standalone database admin tool. You can also delete data using Manager. For details, see the Maintenance tab section.

To purge unwanted data from your Trellix IPS database using the standalone Database Admin tool:

Steps:

  1. Make sure the Manager is shutdown.

  2. Navigate to <Manager_Install_Dir>\bin.

    Note

    The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

  3. Execute the dbadmin.bat file. The standalone Database Admin tool opens.

    Note

    You can also use dbpurge.bat to delete unwanted data from your Trellix IPS database. However, Trellix strongly encourages you to use dbadmin.bat for all your database administration tasks.

  4. Select Maintenance → DB Purge.

    The Alert and Packet Log/Host Event Deletion Tool window is displayed.

    Database Admin Tools - DB Purge Tab
    Database Admin Tools - DB Purge Tab


  5. Specify if you want to Perform DB Tuning after the Purge Operation. You can perform database tuning separately from the purge operation.

    Alert and Packet Log data

    1. Type the Number of days of Alerts and Packet Log data to be preserved. For example, to delete alerts and packet logs older than 90 days, enter 90. You can specify a value between 0 and 9999.

    2. Type the Number of Alerts to be preserved in the database. You can specify a value between 0 and 1,000,000.

      For example, if you enter Number of days of Alerts and Packet Log data to be preserved as 30 and Number of Alerts to be preserved as 2000, then only the latest 2000 alerts and packet logs generated over the last 30 days are retained in the database.

    Host Event data

    1. Type the Number of days of Host Event data to be preserved: You can specify a value between 0 and 9999.

    2. Type the Number of Host Entries to be preserved: Describes the number of quarantined host entries that can be preserved. You can specify a value between 0 and 9999.

    For example, enter Number of days of Host Event data to be preserved as 60 and Number of Host Entries to be preserved as 6000. Assume that the Manager database contains host event data for 100 days. When you click Purge, host events of the oldest 40 days will be removed first. Out of the remaining host events for the most recent 60 days, if there are 8000 host entries, 2000 host entries will be removed. If there are only 5000 entries, all the entries will be preserved.

    Important

    The tool considers the value entered in Number of days of Host Event data to be preserved first irrespective of the value entered in Number of Host Entries to be preserved.

    Application Data

    Specify the Application data that you want to preserve using the following fields:

    1. Number of days of Raw Application data to be preserved

    2. Number of days of Hourly Application data to be preserved

    3. Number of days of Daily Application data to be preserved

    4. Number of weeks of weekly Application data to be preserved

    5. Number of months of monthly Application data to be preserved

    Sensor Performance data

    Specify the Sensor performance data that you want to preserve using the following fields:

    1. Number of days of Raw performance data to be preserved

    2. Number of days of Hourly performance data to be preserved

    3. Number of days of Daily performance data to be preserved

    4. Number of weeks of weekly performance data to be preserved

    5. Number of months of monthly performance data to be preserved

    You can specify a value between 0 and 9999.

    Once you have completed specifying the amount of data to be preserved, click Purge.

    Note

    In cases where purging is aborted for some reason, data that has already been purged is not recovered.

    If you have chosen to tune after purge, then the database is tuned after the purge is complete.