The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Switchover

Prev Next

Switchover, or failover from the Primary to the Secondary, can be manual/voluntary or involuntary.

Note

In a situation where you have planned manual downtime and the downtime is expected to be brief, Trellix recommends that you manually suspend MDR, preventing the Secondary Manager from taking over and becoming active. You can then resume MDR when the downtime period is over.

The Secondary Manager performs regular “health checks” on the Primary Manager. If the Primary Manager is found to be unavailable during a health check by the Secondary Manager, the Secondary Manager waits for a configurable time interval. If the Primary Manager is still unavailable after that time period elapses, control then switches over to the Secondary Manager.

Note

You can switch over to the Secondary manually, as well.

Once the Secondary Manager is active, the Primary moves to standby. The Sensors are made aware of the switchover, communicate with the Secondary Manager, and the system continues to function without interruption.

All “in-flight transactions” are lost upon failover from Primary to Secondary Manager. For instance, if the Primary Manager failed while a user was in the middle of a policy edit, the Secondary Manager will not be able to resume the policy edit.

Note

The MDR feature, in fact, assumes that the Secondary Manager is a standby system, and that it will NOT assume control indefinitely. The Primary Manager should be diagnosed and repaired, and be brought back online.

While the Secondary Manager is active, Trellix recommends against making any configuration modifications on the Secondary Manager, as these modifications could cause potential data synchronization problems when the Primary Manager is resurrected.

Once the Primary Manager has recovered, you can switch control back to the Primary system. During this switch back, if you have made configuration changes on the Secondary, you have a choice whether to retain the configuration on the Primary or overwrite with changes made on the Secondary. After switch-back, alert and packet log data is copied from Secondary to Primary Manager, and can be viewed in the Attack Log page. Data is re-synchronized, the Sensors return to communicating with the Primary, and the system is restored with the Primary Manager active and the Secondary Manager in standby mode.

Note

You can easily dissolve the MDR relationship between the two Managers and return either Manager to stand-alone mode.