The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Recovering malware-object events after a failure using the CLI

Prev Next

Use the commands in this section to recover malware-object events. Perform this procedure from the peer appliance, not from the appliance that failed.

To recover malware-object events:
  1. Log in to the peer appliance.

  2. Enable the CLI configuration mode:

    hostname > enable
    hostname # configure terminal
    hostname (config) #
  3. Recover the events:

    hostname (config) # object-analysis salvage from "YYYY/MM/DD HH:MM:SS"

    where YYYY/MM/DD HH:MM:SS is the date and time from which to start recovering events.

    The number of salvaged objects will be displayed.

    Note

    You can also view the number of salvaged objects using the show object-analysis command.

  4. Save your changes:

    hostname (config) # write memory
Example

The following example salvages the objects that passed through the defective appliance's monitoring port after 12:00 noon on January 25, 2016.

hostname (config) # object-analysis salvage from "2016/01/25 12:00:00"
Total objects salvaged: 25
nx-2 (config) # show object-analysis
...
Total salvaged object analysis entries   :    25