You can restore archived alerts and packet logs from either the Trellix IPS user interface or from the standalone Database Admin tool. However, you can avoid the additional workload on Manager by using the Database Admin tool.
To restore data, the archived data should either be in Manager server or in a computer that is accessible from Manager server. You can also filter data from an archived file and restore just the filtered data. Suppose that there is an archived file containing data generated between Jan 1 and Jan 10. Then you can filter the data generated between Jan 1 and Jan 5 from the archived file and restore just this data.
To restore alerts and packet logs using the standalone Database Admin tool:
Steps:
Navigate to
%programfiles%\Trellix\IPS Manager\App\bin.Execute the dbadmin.bat file. The standalone tool opens.
Select Archival → Alert Restore.
Database Admin Tools - Archival Alert Restore tab.jpg)
Do the following:
Click Browse to locate the archival or type the file's absolute path name.
Select the archived file from the List of Archived Files and then click Restore.
Note
Archived data in the
%programfiles%\Trellix\IPS Manager\App\alertarchivalare listed under List of Archived Files.
Filter the data in the archived file by specifying the start date and time and the end date and time. Only those alerts and packet logs generated during this time frame are restored from the archived file.
Note
The start date and time and the end date and time displayed by default in this window indicate the time frame of the archived data that you have selected to restore. Therefore, if you choose the default dates and times, all the data in the archived file will be restored.
Click Restore.
Enter your database user name and password to complete the restoration process.
Note
Manager server only permits 300,000 alerts to be restored at a time if filtering is applied. If your archive contains more than 300,000 alerts and you set filtering parameters, you will need to perform the restoration process multiple times. For example, if your archival still contains 750,000 alerts after filtering parameters have been met, you will have to restore three times: 1) 300,000 2) 300,000 3) 150,000.
To see the alerts restored in attack log, run solr import.
Note
To run solr import, refer to Trellix Intrusion Prevention System Installation Guide.