The archiving feature allows you to store old data in a remote location when you run out of storage space. The use of archiving is optional and can't be used as an alternative to Direct Attached Storage (DAS), Trellix ESM - ELM , or Trellix ESM - ELS.
You can allocate the amount of storage and set up the percentage of space that alerts, flows, and logs occupy. The database deletes partitions when those parameters have been exceeded.
To query archived partitions, select the feature (add the clickstream) and set the date of the archive you want to search.
In general,
Don't use data storage archiving in a clustered environment. Use sharing or add a DAS to the system.
If your situation mandates data storage archiving, make sure it is enabled on all nodes in the cluster and that the archival share paths are different for each node.
Note
Configuring the same archival share path for multiple nodes might result in data loss.
Purpose
The archive is primarily for customers who don't have a DAS. It provides space on the Trellix ESM to hold the minimum needed data.
Note
It is not a recommended method for increasing Trellix ESM storage capacity. Querying data in archived partitions is very slow compare to querying data on the Trellix ESM
Use
AD1 is the mount point for remote archive storage. You can use Network File System (NFS), Common Internet File System (CIFS), Storage Area Network (SAN), or Internet Small Computer System Interface (iSCSI) for AD1.