Back up your data (event, flow, log, and packet and string map tables) regularly to make sure that you can restore information if you encounter a data loss.
You can't restore data from a backup of a previous Trellix ESM version. Backups are only compatible with the current version of Trellix ESM.
To allow larger backup files, use ext4 as your NFS server file system.
Data backups are incremental.
When you trigger a new backup (either manually or automatically), the system backs up only the data generated since the last backup.
Note
If no previous backup exists, the system performs a full backup.
From the Trellix ESM dashboard, click
and select System Properties.To schedule an automatic backup, select → .
Determine how often to back up data. You can also set the time of day for the backup.
Note
To prevent oversized backup files, configure daily backups.
Identify the remote location where you want to save the data.
Test the connection by clicking Connect.
To complete a manual backup now, click Back up now.
Note
Do not rename backup files because the system can only restore backups of files that match system-generated names. You can't back up (automatic or manual) or restore data if another backup or restore is already in progress.
Trellix ESM creates a compressed data file at the location you set.