Restoring your backed up data means you want to return to a previous configuration of your Trellix IPS, or to a previous collection of alert data, or both, which may include different Sensor port configurations, policy applications, and so forth. Note that the Manager server must be shut down during a restore; thus, all Manager activities must be stopped to complete a restore.
When restoring configuration tables (All Tables or Config Tables), you must de-install your Sensors using the Sensor CLI command deinstall, then re-install your Sensors using the set sensor sharedsecretkey command.
If your Sensor or interface configurations have changed since the last backup, you may need to re-wire your segments to match the backed up configuration's monitoring settings. Test restoration of backups periodically to ensure that a backup was successful and valid. The best way to do this is to perform a "test" restore of the backup on a Secondary, non-production Manager.
Note the following before attempting to restore a backup:
Manager Version: You can restore database backup from an older version of the Manager to a newer version of the Manager if they belong to the same major version. For example a back up from an older version of the 11.1 manager can be restored on a newer 11.1 Manager version.
Config Tables version
You can restore the Config Tables only if the major versions of the backed up Manager and the present Manager match. For example, a backup from any 10.1 Manager version can be restored on any other 10.1 Manager version. A backup from a 10.1 Manager cannot be restored on a 11.1 Manager.
You cannot restore the Config Tables of a later version of the Manager on an earlier version of the Manager. For example, you cannot back up the Config Tables from Manager version 10.1.7.65 and restore it on Manager version 10.1.7.50.
All Tables version: You can restore All Tables only if the versions of the backed up Manager and the present Manager match exactly (all four digits).
To restore using the standalone Database Admin tool, do the following:
Steps:
Stop the Manager server service.
Follow one of the following methods to stop the Manager service:
Right-click on the Manager icon at the bottom-right corner of your server and stop the service.
Select Windows Control Panel → Administrative Tools → Services. Then right-click on Trellix IPS Manager service and select Stop.
Navigate to
<Manager_Install_Dir>\bin.Note
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.Execute the dbadmin.bat file. The standalone tool opens.
Note
You can also use dbbackup.bat to back up and restore data. However, you will be directed to use dbadmin.bat for all your database administration tasks.
You see the Database Admin Tools window.
Click the DB Restore tab.
Database Admin Tools - DB Restore Tab.jpg)
Select a backup from the table.
All the backups taken through the DB Admin tool are displayed (that is, the backup file copied from another directory is not displayed). Place the mouse cursor over a backup to view file information in a pop-up.
Note
If the backup file is stored at a location different from the default one, use the Browse button to locate it.
Click Restore.
Note
During a restore, Manager needs to be shutdown. Since Manager is closed to all communications, no alert data sent from the Sensors is received. Manager system log and ems.log will note "Restore in Progress" faults during this process.
A pop-up prompts you for the database user name and password.
Type the database User Name and Password. This information was entered during Manager installation.
Note
For MariaDB, this is not the MariaDB root administrator password.
After the restore process is complete, the following message is displayed: "Database restore successful, Restart Manager Service." Ensure that all Java processes are terminated and then restart Manager service (on Manager server). Wait a few seconds for Manager service to restart before attempting to log in.
Caution
Ensure that no Java processes are running when restarting Manager service. Otherwise, Manager may experience errors.
Note
If the Manager is running on software version 10.1.7.40 or below, you must run the Apache Solr script after restoring database in the Manager to view the alerts in the Attack Logpage. For more information, refer to the section Run the Apache Solr Scripts in Trellix Intrusion Prevention System Installation Guide. If the Manager is running on software version 10.1.7.44 or above, it should be able to import the Solr data automatically. In case you do not see the alerts appearing in theAttack Log page even after restoring the database, you need to run SolrDB import manually in the Manager. For more information, refer to the section Alerts do not show up in Attack Log or on dashboards after upgrading the Manager.