The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create and manage Trellix ESM clusters

Prev Next

Connect multiple Trellix ESMs to speed up processing and provide data redundancy.

When you create a cluster, use the same model of Trellix ESMs for better performance. For information about connector and equipment types, see Trellix Enterprise Security Manager Hardware Guide.

Note

After changing cluster configurations, you need to write the new settings to devices.

  1. Create a cluster.

    1. From System Properties, click Clustering.

    2. On the Nodes tab, click Create New.

    3. In the Node Configuration window, type a name for the node. This is the name shown on the Nodes tab of the Clustering pane.

    4. Enter the IP address or URL of the Trellix ESM you want to add.

    5. Select the data center that the cluster is associated with.

    6. Enter the credentials needed to log on to the Trellix ESM, then click Next.

      Trellix ESM tests the connection to the new device and adds it to the cluster.

    7. Select the number of Replicas (the number of copies of your data the nodes maintain).

    8. On the System PropertiesClustering page, select the new Trellix ESM and click Key Selected.

  2. Configure node settings.

    1. Select a node and click Edit Selected.

    2. Configure the interface, proxy, and other settings.

  3. Manage cluster settings.

    1. Select the number of replicas for the cluster. This is the number of backup copies of data that the system maintains.

    2. Set the Databus Management Port. This is the port used to send configuration data to the devices in the cluster.

    3. Set the Databus Data Port. Event and flow data is transmitted through this port.

  4. Add nodes to a cluster.

    1. From System Properties, click Clustering.

    2. On the Nodes tab, click Create New.

    3. In the Node Configuration window, type a name for the node. This is the name shown on the Nodes tab of the Clustering pane.

    4. Type the IP address or URL of the Trellix ESM you want to add.

    5. Select the data center that the cluster is associated with.

    6. Type the credentials needed to log on to the Trellix ESM, then click Next.

      Trellix ESM tests the connection to the new device and adds it to the cluster.

    7. Select the number of Replicas (the number of copies of your data the nodes maintain).

    8. On the System PropertiesClustering page, select the new Trellix ESM and click Key Selected.

  5. To promote a node to the management node, log on to the non-management node with primary user or power user credentials and click Promote.

  6. Click Write to send configuration data to the devices in the cluster.