The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Standalone Manager upgrade on Windows operating system

Prev Next

Prerequisites:

  • If you are using Central Manager, it must be upgraded to 11.1 before you upgrade the Manager.

  • Your current Trellix IPS infrastructure meets all the requirements discussed in Reviewing the upgrade requirements.

  • If you want to upgrade the RAM on the Manager server, make sure you do that before you begin the Manager upgrade.

  • You have reviewed and understood the implications of the upgrade considerations discussed in Reviewing the Upgrade Considerations.

  • You have backed up your current Manager data. See Performing a database backup.

  • As a best practice, make sure all the devices are communicating with the Manager and your deployment is working as configured. This ensures that you do not upgrade with any existing issues.

  • You have the latest 11.1 Manager installable file at hand. You can download it from the Trellix Download Server.

  • You have your Manager database root password available.

  • You have stopped all third-party applications such as Security Information and Event Management (SIEM) agents. It is especially important that you stop any such third-party application that communicates with the Manager database. The Manager cannot upgrade the database if the database is actively communicating with another application.

    Important

    If this is an upgrade of a Manager in an MDR pair, then you should switch the primary Manager to standby mode before you upgrade. Make sure you are following the steps in MDR Manager upgrade.

The following are the tasks to upgrade a standalone Manager.

Steps:

  1. Stop the Manager service.

    Right-click on the Manager icon at the bottom-right corner of your server and stop the service. Alternatively, go to Windows Control Panel → Administrative Tools → Services. Then right-click on Trellix IPS Manager and click Stop.

  2. Stop the Trellix IPS Manager Watchdog service using the same method as described to stop the Manager service.

    Note

    Make sure the Trellix IPS Manager Database service remains started.

  3. Exit the Manager tray from the Windows Task Bar.

  4. Move any saved report files and alert archives from the server to some other location.

    The reports are saved at <Manager_Install_Dir>\REPORTS folder. The alert archives are saved at <Manager_Install_Dir>\App\alertarchival folder.

  5. Run the 11.1 Manager executable.

    Note

    To ensure a successful upgrade, close all the applications and temporarily disable any 3rd-party processes, such as SIEM agents, that might be communicating with the Manager. The Manager installer wizard displays the following warning message to recommend you to close all the applications.

    GUID-A8036BDF-302D-44C8-99BD-ED58FC05B2E7-low.jpg

    Caution

    After providing the MariaDB password, you will not be able to proceed with the upgrade process if you have configured any M-series Sensor in the Manager. An Upgrade Failure error is displayed:

    Upgrade Failure
    Upgrade Failure


    To continue with the upgrade process, disconnect any M-series Sensors configured in the 10.1 Manager and restart the upgrade process.

    Important

    • You can generate configuration reports for a selected M-series Sensor for future reference from Manager → <Admin Domain Name> → Reporting → Configuration Reports → IPS Sensor. For more information, see Generate IPS Sensor reportsin Trellix Intrusion Prevention System 11.1.x Product Guide.

    • A list of all M-series Sensors are provided in SensorModel.log file on desktop. To view the complete domain path for the required M-series Sensors, go to Devices → <Admin Domain Name> → Global → Device Manager. Select the required M-series Sensor from Sensors tab and view the domain details from Owner Domain column. By default, the Owner Domain column is not enabled. To enable it, go to Device Details drop-down and select Columns → Device Details → Owner Domain.

  6. At the end of the upgrade process, you might be required to restart the server. If prompted, it is highly recommended that you restart the server.

    • Select Yes, restart my system to restart the server immediately.

    • Select No, I will restart my system myself to complete the upgrade process without restarting the server. You can restart the server at a later point in time. Clicking Done in the Manager Installation Wizard will start the Manager services.

  7. During the upgrade, you might have been prompted to run the Apache Solr script on the Manager server. After the upgrade is complete, run the script only if you had been prompted to do so.

  8. Log in to the Manager.

    You can verify the version in the Dashboard page.

  9. Go to Manager → <Admin Domain Name> → Troubleshooting → Logs. Check the Faults tab to ensure that the Manager is up.

    Refer to the following sections and complete those tasks.

    1. Make sure the Manager contains the latest signature set.

    2. Upgrade the Sensor software with the latest signature set. See Performing Signature Set and Sensor Software upgrade.

    Note

    The default Manager root directory for App, MariaDB, and Solr will be moved from <System_Drive>\Program Files\McAfee\Network Security Manager to <System_Drive>\Program Files\Trellix\IPS Manager. In such scenarios, the Manager installer will prompt this directory change window.

    The customized root directory will remain the same.