You can manually mark standby malware-object events from file submissions for a specified time period "active" on the peer appliance. This is useful when one of the appliances in the HA pair fails and is removed from the Central Management System appliance. The alerts that were aggregated to the Central Management System appliance and attributed to the failed appliance remain on the Central Management System appliance, but you will be unable to expand the alerts attributed to the failed appliance or submit them to a managed Malware Analysis appliance for deeper forensic analysis. After you mark the events "active" on the peer appliance, they are aggregated to the Central Management System appliance again, but this time they are attributed to the peer appliance. This results in duplicate alerts on the Central Management System appliance, but the alert details and the ability to submit to the Malware Analysis appliance are restored.
If the primary appliance (the appliance with the full license) fails, the secondary appliance (the appliance with the restricted license) functions as the primary appliance for 90 days, until its license grace period ends. You should replace the failed appliance within the grace period to prevent any detection loss. After the grace period ends, the appliance loses its detection capabilities.
Prerequisites
Admin access