Trellix DLP Network appliances ship with replaceable hard drives. Each appliance uses hot-swappable hard drives connected to a RAID controller. The RAID controller allows the system to continue operating if a single hard drive fails. A single failed hard drive can be replaced while the system is still operational.
Caution
Use only the replacement hard drives provided by Trellix. Do not reseat hard drives unless directed to by Technical Support.
Identify the failed hard drive.
The Trellix DLP log files contain information about which drive failed.
Using a command-line session, log on to the appliance.
Generate the .zip file that contains the logs using one of these methods.
From the console menu, select Generate MER and follow the on-screen instructions.
From the shell, run:
sudo /opt/McAfee/ldt/getlogs/getlogs.sh
If you use the shell script, the file is located in /tmp and the file name is based on the appliance and the current time. You can use SCP to copy the files from the appliance.
Provide these logs to technical support when requesting replacement hardware.
Remove the failed hard drive from the appliance.
Press the latch on the failed hard drive to release the spring-loaded handle.
Pull on the handle to remove the failed hard drive from the appliance.
On the replacement hard drive, press the latch to release the spring-loaded handle.
Insert the replacement hard drive into the appliance.
Slide the drive into the empty hard drive bay until it is fully seated.
Press the handle until it latches.
If the appliance is turned off, turn it on.
After the drive is inserted, the RAID controller begins the rebuild operation. Performance is reduced while the rebuild operation takes place.
Caution
Do not turn off the appliance until the rebuild operation is complete.