The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Set up a schedule for file pruning

Prev Next

The File and Database Pruning option enables you to set a schedule by which generated log data and files are deleted from your Manager/database. These data/files are admin created through various System Configuration actions, and each details a different aspect of system functionality. These system files get larger as more data is added over time. File pruning allows you to delete the data in a log or an entire static file either at the next scheduled time or in a set number of days. Regular deletion saves disk space on Manager server, thus improving overall performance.

The deletion scheduler works as follows: First, you set a daily time when you want File pruning (that is deletion) to take place; this is under the Maintenance Scheduler setting. Next, for each file type, you set a number of days/file size (Scheduled Deletion) after which you want a file that has reached the set age/size to be deleted. On the day a file is to be deleted, deletion takes place at the set daily time.

Note

When scheduling File pruning, set a time when no other scheduled functions (archives, backups, database tuning) are running. The time should be a minimum of an hour after/before other scheduled actions.

To schedule deletion for Manager and database files, do the following:

Steps:

  1. Select Manager → <Admin Domain Name> → Maintenance → Database Pruning → File and Database Pruning.

    Note

    To schedule file pruning action in the Central Manager, select Manager → Maintenance → Database Pruning → File and Database Pruning.

  2. Select Yes against Enable File and Database Pruning? to enable automatic file pruning.

    This overrides the enabled status of individual file types from the table.

  3. Select the day (Recur every) on which automatic file pruning will occur. Saturday is the default.

  4. Set the time (Start Time: At Hr and Min) for the selected day when you want scheduled maintenance to occur. The default is 23:30 hours.

  5. View the list of files/logs for which you can set maintenance:

    Note

    The default enabled status for each file/log is listed in parentheses after each description that follows.

    • Manager Files

      • Diagnostics — Files created by performing the steps in Uploading a diagnostics trace from a Sensor to your Manager. (Yes)

      • Sig Files (*.bin) — Files created during signature files update from the Manager to the Sensor by performing the steps in Updating the configuration of all Sensors. (No)

      • DoS Files — Denial of service (DoS) profiles uploaded from your Sensors. These files are downloaded by performing the steps in Managing DoS Learning Mode profiles on a Sensor. (Yes)

      • Backup Files — Saved Manager configuration, audit, and/or alert data as created by performing the steps in Backing up and restoring data. (Yes)

      • Saved Reports — All saved scheduled reports created by performing the steps in Scheduling a report. (Yes)

      • Daily Archival — Those archivals scheduled as Daily when Scheduling automatic archival.

      • Weekly Archival — Those archivals scheduled as Weekly when Scheduling automatic archival.

      • Monthly Archival — Those archivals scheduled as Monthly when Scheduling automatic archival.

      • Packet Capture Files — Manager can be configured to capture traffic on any port for a particular duration or size. These captured files reside under Packet Capture Files.

      • Archived Malware File Reports — All reports fetched from IVX and Intelligent Sandbox

      • Archived Malware Files - Executables — All executable malware files

      • Arachived Malware Files - Office Files — All the office files like Excel, Word, and so on

      • Archived Malware Files - PDFs — All the PDF files

      • Archived Malware Files - Flash Files — All the flash files

      • Archived Malware Files - Compressed Files — All compressed files

      • Archived Malware Files - APK Files — All APK files

      • Archived Malware Files - JAR Files — All JAR files

      • Archived Malware Files - Script Files — All Script files

    • Database Data

      • Audit Log — Log detailing user activity. Data is deleted by timestamp; the file itself is never deleted. This file can be viewed by performing the steps in Generating a User Activities Audit. (Yes)

      • Fault Log Data — Log detailing system faults. Data is deleted by timestamp; the file itself is never deleted. (Yes)

      • Hourly Data Mining — Deletes trend data collected for trend analysis resources on an hourly basis. (No)

      • Daily Data Mining — Deletes trend data collected for trend analysis on daily basis. (No)

      • Performance Monitor Raw Data — Raw data relating to performance monitoring (data polled from the Sensor every 3 minutes).

      • Performance Monitor Hourly Data — Data pertaining to performance monitoring. The data is captured hourly.

      • Performance Monitor Daily Data — Data pertaining to performance monitoring. The data is captured daily.

      • Performance Monitor Weekly Data — Data pertaining to performance monitoring. The data is captured weekly.

      • Performance Monitor Monthly Data — Data pertaining to performance monitoring. The data is captured monthly.

      • Application Visualisation Raw Data — Raw data relating to Application Visualisation.

      • Application Visualisation Hourly Data — Data pertaining to Application Visualisation. The data is captured hourly.

      • Application Visualisation Daily Data — Data pertaining to Application Visualisation. The data is captured daily.

      • Application Visualisation Weekly Data — Data pertaining to Application Visualisation. The data is captured weekly.

      • Application Visualisation Monthly Data — Data pertaining to Application Visualisation. The data is captured monthly.

      • Device Profile Data —Data relating to any remote computing device to decipher its operating system and device type. The remote computing device can be any endpoint inside or outside the network.

      • Incident Data — All generated incidents in the system marked as incident. The reported attacks are logged as incidents.

  6. Select Yes for those file types that you want to be deleted at the scheduled time.

  7. For those file types for which you have enabled deletion, type the time duration after which you want the files to be deleted.

  8. Click Save when you are done with your changes.

  9. (Optional) Click GUID-DE8F9231-1BB5-42A7-B78B-1FDD431543A8-low.png to update the information displayed in the page. Go to Manager → <Admin Domain Name> → Maintenance → Scheduler Details to view the overall scheduled tasks in the Manager.

    File Maintenance Scheduler Settings
    File Maintenance Scheduler Settings


    Note

    Data on performance monitoring is displayed only when it is enabled from Devices → <Admin Domain Name> → Global → Common Device Settings → Performance Monitoring → Enable.

    Note

    By default, pruning is enabled for application visualization data, malware data, and performance monitor data and the default duration will be 90 days, 12 weeks, and 3 months respectively.

    Note

    When you upgrade from earlier versions of the Manager, the default values will be applied to application visualization data, malware data, and performance monitor data. If you had pruning enabled with a set duration in the earlier version of Manager, the values will get migrated to the latest Manager. If pruning was not enabled in the previous version, it will be enabled after the upgrade with the default values.