The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure a Trellix Enterprise Security Manager - Enterprise Log Manager device

Prev Next

Set up your Trellix Enterprise Security Manager - Enterprise Log Manager to compress data and to store multiple copies of data.

  • Your system must include a standalone Trellix ESM - ELM.

  • Configure a standby Trellix ESM - ELM but don't add it to the console.

  • Make sure that there is no data on the standby Trellix ESM - ELM.

  1. Set Trellix ESM - ELM compression.

    1. On the system navigation tree, select the ELM, then click the properties icon. GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png

    2. Click ELM ConfigurationCompression.

    3. Select the ELM compression level, then click OK.

  2. Set up ELM redundancy.

    1. On the ELM Properties page, click ELM Redundancy, then click Enable.

    2. Type the IP address and password for the standby ELM, then click OK.

    3. On the ELM Properties page, click Storage Pools, and verify that the Active tab is selected.

    4. Add storage devices to the active ELM.

    5. Click the Standby tab, then add storage devices that have enough combined space to match the storage on the active ELM.

    6. Add one or more storage pools to each ELM.

    7. To switch the standby ELM to primary, click Switch ELMs. Logging and configuration actions are locked during the switch-over process.

    8. For troubleshooting, you can stop a standby ELM by clicking Suspend and start it by clicking Return to Service.