The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Distributed search

Prev Next

Distributed search enables you to search across multiple NDR devices and retrieve PCAP data from multiple PX packet capture appliances. Distributed search requires one NDR appliance set up as the director node and other NDR appliances set up as the data nodes. This setup is similar to the NDR cluster setup. See Clusters.

IA-Director.jpg

Distributed Search

Distributed Search Components

Definitions

Director node

An NDR appliance that is a centralized location from which to initiate distributed searches to the data nodes. The director node does not collect metadata directly from NDR data nodes or PX appliances but can pull PCAP from any connected PX appliance.

Note

By default, all NDR appliances are configured as a master data node. Use the CLI to change your NDR appliance master data node configuration to a director.

Master data node

An NDR appliance that is connected to one PX appliance and one or more NDR data nodes or multiple PX appliances and one or more NDR data nodes. The master data node collects metadata from connected PX appliances and shares the data load across the connected NDR data nodes.

Data node

NDR appliances connected to the Master Data Node and used to store and search metadata.

In distributed search, multiple NDR appliances, known as NDR clusters, operate independently. NDR director nodes query these devices. This approach relies on Elasticsearch tribe nodes to operate.

To configure NDR for distributed search, open the following ports on any firewall between the data nodes and the director node:

  • TCP 22 on both sides.

  • TCP and UDP 1194 on both sides.

Converting an NDR series appliance to a director node

Converting an NDR appliance to a director node erases Elasticsearch data, and the appliance becomes an aggregation unit.

Perform this procedure on the NDR Series appliance that you want to convert to a director node.

Caution

Converting a Trellix NDR console to a director node is irreversible. You cannot revert an appliance to standard console mode without performing a factory default reset. Running a factory default reset permanently erases all system configurations, search indexes, and collected data.

To convert an NDR Series appliance into a director node in the CLI:

Your NDR appliance is now a director node. You must add master data nodes to the configuration. See Adding data nodes to the director node.

Revert a director node to a standard console

To convert a director node back to a standard Trellix NDR console, you must perform a factory default reset.

Warning

Executing a factory default reset permanently deletes all data, logs, and configurations from the appliance. Back up critical data before proceeding.

Prerequisites:

You must have administrative access credentials (npadmin) to the CLI.

  1. Log in to the Trellix NDR console CLI as npadmin.

  2. Enter privileged mode: enable

  3. Enter the npadmin password.

  4. Enter configuration mode: configure system

  5. Run the factory default reset command: make-factory-defaults

  6. Confirm the system prompt to clear all appliance data and restore factory default settings.

Director menu options reference

When you enter director configuration mode (enable > configure system > director), the CLI displays the director menu options.

NDR_images_Direcor_menu.png

The following table describes all available options in the director menu:

Menu Option

Description

#: Data Nodes

Displays all data nodes currently connected to the director node.

#: Delete Data Node

Removes the selected data node from the director node configuration.

A: Add Data Node

Adds a data node or cluster master to the director node configuration package.

S: Configure Openvpn Subnet

Defines the subnet from which an IP address is allocated to the OpenVPN tunnel interface on a connected master node. Each director node requires a distinct subnet.

I: Configure Openvpn ServerID

Specifies the unique server identification IP address of the director node for OpenVPN client connections.

P: Configure Openvpn Protocol

Specifies the transmission protocol for OpenVPN traffic (udp or tcp).

C: Cancel without saving changes

Discards all uncommitted menu edits and exits director configuration mode.

Q: Quit and save changes

Commits all configuration changes and exits director configuration mode.

Converting an NDR Series Appliance into a Data Node

Converting an NDR Series appliance to a data node stops indexing and Elasticsearch while the change takes effect. Perform this procedure on the NDR Series appliance that you would like to convert to a data node.

To convert an NDR Series appliance to a data node:

Adding data nodes to the director node

You must add the data nodes to the director node. Perform this procedure on the director node.

To add data nodes to the director node:

You must now go to the data node CLI and associate it with this director. This is explained in Adding a data node to the director node.

Adding a data node to the director node

This section provides instructions for adding your NDR data node to your NDR director node.

To add a data node to the director node:

Removing a data node from the director node

Perform this procedure on the data node that you would like to remove from the director node.

To remove a data node from the director node: