The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Data Storage Archiving (AD1)

Prev Next

The archiving feature allows you to store old data in a remote location when you run out of storage space. The use of archiving is optional and can't be used as an alternative to Direct Attached Storage (DAS), Trellix ESM - ELM , or Trellix ESM - ELS.

You can allocate the amount of storage and set up the percentage of space that alerts, flows, and logs occupy. The database deletes partitions when those parameters have been exceeded.

To query archived partitions, select the feature (add the clickstream) and set the date of the archive you want to search.

In general,

  • Don't use data storage archiving in a clustered environment. Use sharing or add a DAS to the system.

  • If your situation mandates data storage archiving, make sure it is enabled on all nodes in the cluster and that the archival share paths are different for each node.

    Note

    Configuring the same archival share path for multiple nodes might result in data loss.

Purpose

The archive is primarily for customers who don't have a DAS. It provides space on the Trellix ESM to hold the minimum needed data.

Note

It is not a recommended method for increasing Trellix ESM storage capacity. Querying data in archived partitions is very slow compare to querying data on the Trellix ESM

Use

AD1 is the mount point for remote archive storage. You can use Network File System (NFS), Common Internet File System (CIFS), Storage Area Network (SAN), or Internet Small Computer System Interface (iSCSI) for AD1.