Network security is an ongoing process that requires a long-term plan for archiving and maintaining your database for the alerts and packet logs generated by your deployed Sensors. Archiving this information is necessary for historical analysis of alerts that may help you better protect your network in the future.
All sizing estimates are based on tests of various alert/log generation frequencies. Multiple frequency and file size parameters are offered to help you better prepare your database for long-term maintenance.
As alerts and packet logs gradually accumulate in your database, the disk space allotted to your Trellix IPS processes will require thoughtful planning and maintenance to keep up with the frequency and size of incoming data. Depending on your archiving needs, it is essential that you understand the database space required to maintain an efficient system.
One question to ask yourself is: "If my Sensors generate one alert every ten seconds for a year, how much database space will I need to maintain all of these alerts?"
With that question in mind, the following topics are presented to help you get the most out of Trellix IPS Manager and database:
Capacity planning— Ensure that resource requirements are met for optimal performance.
Database maintenance and tuning— Perform regular database tuning to ensure optimal performance.
Database backup and recovery— Backup and archive to protect against hardware/software failure.
Maintenance tab in Manager— File pruning of the generated log data and files.
Using the Database Admin Tool— A standalone tool for maintaining your Manager database.