The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Prepare for Trellix OS Manager fresh virtual machine instance deployment

Prev Next

Warning

  • You cannot perform a direct upgrade from 11.1 Update 9 (MLOS) to Trellix OS Manager using the upgrade command. To install the Trellix OS Manager on a VM, you must perform a fresh deployment and restore the All Table Backup.

  • This procedure applies only to virtual machine instances (ESX, KVM, Nutanix, or Cloud).

Pre-deployment process:

To ensure data integrity and a smooth transition, follow these requirements to upgrade your Manager from 11.1 Update 9 (MLOS) to Trellix OS.

Prerequisites:

Important

Mandatory actions apply to Manager/Central Manager configurations (standalone, primary, and secondary).

  1. Verify that the Manager server uses Trellix IPS Manager version 11.1.7.136 or 11.1.7.136.2.

  2. Ensure that the remote client machine used to copy files and folders from the MLOS Manager has SSH version 9.0 or later.

    To verify the current SSH version, execute the command ssh -V.

  3. You must keep the SSH keepalive configuration enabled in your SSH client (Example: Bitvise, MobaXterm) to avoid session termination in the Linux-based Manager and maintain a stable connection during the Manager upgrade process.

    Mobaxterm.png
  4. Record the MLOS Manager's IP address and hostname; use this same information for the Trellix OS Manager.

    Execute the commands:

    • show network ip: Collect the IP address.

    • show network hostname: Collect the hostname.

  5. Carefully document all customization done in the MLOS setup, as it must be repeated post-migration.

Mandatory actions before deploying the Trellix OS Manager:

  1. Take the "All Table Backup" from MLOS and move it to an external disk. When the backup is generated, two files are created with the .jar and .dmp extensions. Back up the .jar and .dmp files to a safe location in the remote machine.

    To verify a successful backup:

    • Execute the following commands in sequence to check if the latest backup file is available:

      1. moveManualBackups

      2. show files

    • Go to Manager → <Admin Domain Name> → Troubleshooting → Logs page and select Background Tasks tab to confirm the backup is complete.

    • Execute the command show log file dbadmin.log and verify the success statement in the log file. If any issue persists, contact Trellix support.

  2. When you are taking a backup from a secondary standby Manager, perform the following steps:

    1. Execute the command, run dbBackup.sh.

    2. When prompted for backup type, select ALL TABLES backup.

    3. When prompted for a list of actions, bypass the comment option.

  3. The following folders must be copied from the MLOS system to the remote client machine in a safe location using SFTP.

    Tip

    Trellix recommends using Bitvise to transfer the files/folders.

    • /opt/IPSManager/App/temp

    • /opt/IPSManager/App/Backups

    • /opt/IPSManager/App/alertarchival

    • /opt/IPSManager/App/CCMigration

    • /opt/IPSManager/App/config

For steps on installing the Manager, refer to sections Create a Manager instance using the OVA file and Create a Manager instance using a qcow2 file.

Post-deployment process:

After deploying Trellix OS Manager, perform a data restore to load all your original data onto the new operating system.

Prerequisite:

  1. Enable the SFTP and SCP features on the Trellix OS machine to copy files from the remote machine.

    Execute the following commands in sequence:

    1. enable

    2. configure terminal

    3. ssh server services file-transfer scp enable

    4. ssh server services file-transfer sftp enable

    5. write memory

Mandatory actions post deployment:

  1. Stop the Manager service by using no ipsmanager enable.

  2. Restore the "All Table Backup" files in Trellix OS Manager.

    Execute the following commands in sequence:

    1. enable

    2. configure terminal

    3. To list the latest backup files, execute the command:

      show ipsmanager backups

    4. ipsmanager database restore path /opt/IPSManager/App/Backups/AllTablesBackup.jar

    5. show ipsmanager database restore status

  3. The following folders must be replaced in the Trellix OS system using scp recursively.

    If the backup folders taken from 11.1 Update 9 are located at the path /home/admin/folderbackups on your client machine, replace the temp folder by executing the following command:

    scp -r /home/admin/folderbackups/temp/* admin@10.1.1.1:/opt/IPSManager/App/temp/

    You must repeat the same command for the following folders:

    • /home/admin/folderbackups/temp

    • /home/admin/folderbackups/Backups

    • /home/admin/folderbackups/alertarchival

    • /home/admin/folderbackups/CCMigration

  4. Replace the mlcCerts folder by executing the command:

    scp -r /home/admin/folderbackups/config/mlcCerts/* admin@10.1.1.1:/opt/IPSManager/App/config/mlcCerts/

  5. If the backup folder taken from 11.1 Update 9 is located at the path /home/admin/folderbackups/config on your client machine:

    • Replace the jssecacerts file by executing the following command:

      scp /home/admin/folderbackups/config/jssecacerts admin@10.1.1.1:/opt/IPSManager/App/config/jssecacerts

    • Replace the CustomJSSEcaCerts file by executing the following command:

      scp /home/admin/folderbackups/config/CustomSecurity/CustomJSSEcaCerts admin@10.1.1.1:/opt/IPSManager/App/config/CustomSecurity/CustomJSSEcaCerts

  6. Replacing the ems.properties file:

    1. Identify custom entries added for ems.properties in the 11.1 Update 9 Manager.

    2. Create a new file myEms.properties in the client machine.

    3. Add the custom entries in myEms.properties file.

    4. Update myEms.properties file in Trellix OS. If the file is created in /home/admin/folderbackups/config/myEms.properties, execute the command:

      scp /home/admin/folderbackups/config/myEms.properties admin@10.1.1.1:/opt/IPSManager/App/config/myEms.properties

    Tip

    An automated tool is available to read ems.properties file, identify differences, and update the necessary changes in the new configuration file. For any assistance, contact Trellix support.

  7. Restart MariaDB by using the commands:

    1. enable

    2. configure terminal

    3. no mariadb enable

    4. mariadb enable

  8. Enable the Manager service by using ipsmanager enable.

  9. You must allow time for the Manager to establish trust with the attached Sensors.

  10. Ensure you have downloaded the latest signature set in the Manager.

  11. For the Manager in an MDR pair, restore the database and file backups for the primary and secondary Manager to avoid post-migration issues such as the CA-signed Sensor channel flap issue.

  12. The following table lists the impact of alert data migration in Manager:

    Component

    Impact

    Alert data storage

    Note

    Manager

    Disk is wiped

    Alerts are stored in MariaDB and Solr.

    The Attack Log will have no alerts immediately after All Table Backup restore.

    Alert data gets restored on the Manager startup.

    Expect a delay before the alerts appear in the Attack Log.

    To ensure all alerts are available in the Attack Log, wait for the automated Solr import process to complete. Check Background Tasks for the status.