The responsiveness of the user interface, the Attack Log in particular, has a lasting effect on your overall product satisfaction.
In this section, we suggest some easy but essential steps to ensure that Trellix IPS responsiveness is optimal.
- During Manager software installation, use the recommended values for memory and connection allocation.
- You will experience better performance in your configuration and data forensic tasks by connecting to the Manager from a browser on a client machine. Performance may be slow if you connect to the Manager using a browser on the server machine itself.
- Perform monthly or semi-monthly database purging and tuning. The greater the quantity of alert records stored in the database, the longer it will take for the user interface to parse through those records for display in the Attack Log. The default
Trellix IPS settings err on the side of caution and leave alerts (and their packet logs) in the database until the user explicitly decides to remove them. However, most users can safely remove alerts after 30 days.
Caution
It is imperative that you tune the database after each purge operation. Otherwise, the purge process will fragment the database, which can lead to significant performance degradation.
- Defragment the disks on the Manager on a routine basis, with the exception of the MariaDB directory. The more often you run your defragmenter, the quicker the process will be. Consider defragmenting the disks at least once a month.
Caution
Do NOT attempt to defragment the MariaDB directory using the operating system's defrag utility. Any fragmentation issues in the tables are rectified when you tune the database. For more information on database tuning, see the Trellix Intrusion Prevention System Product Guide.
- Limit the number of alerts to view when opening the Attack Log. This will reduce the total quantity of records the user interface must parse and, therefore, result in a faster initial response on startup.
- When scheduling certain Manager actions (backups, file maintenance, archivals, database tuning), set a time for each that is unique and is a minimum of an hour after/before other scheduled actions. Do not run scheduled actions concurrently.