Include multiple Trellix ESM devices in your architecture to maximize throughput (scaling), to maintain multiple instances of event data (replication), or to take advantage of both of these capabilities in a hybrid installation (both scaling and replication).
In any clustered environment, one node acts as the management node, performing management functions for the cluster. For more information, see Trellix Enterprise Security Manager Installation Guide.
Scaling
Scaling enhances system throughput rates (more events per second) by using the power of multiple Trellix ESM appliances to process event data. When scaled, each Trellix ESM appliance contains a part of the event data. The diagram below shows a three-node Trellix ESM scaled cluster in which each Trellix ESM node contains 1/3 of the data. When a query is executed, each Trellix ESM node processes that query on the data it contains. The results from all nodes are displayed as a single set.
![]() |
Replication
When you use replication, each Trellix ESM device contains a complete copy of the database, allowing you to replicate your data across multiple Trellix ESM devices to reduce the risk of data loss and reduce the need to back up data. In a replicated environment, you specify which Trellix ESM you want as the active device. This device is the primary point of analyst and management interaction.
In addition to hosting copies of your data, the other Trellix ESMs act in a stand-by management capacity. If the primary Trellix ESM fails, one of the standby Trellix ESMs takes over the management functions.
Each Trellix ESM collects new event data directly from the databus. This prevents Trellix ESMs from having to sync event data between each other. Configuration settings, however, are synchronized from the primary Trellix ESM device to other Trellix ESM devices.
![]() |
Scaling and replication together
By using both scaling and replication, you can build a strong system that provides fast processing of events while providing fault tolerance.
![]() |
Enabling ESM replica synchronization
To ensure there is no difference in widget event data between clustered ESM nodes and their corresponding replicas, you can synchronize them. The first time you enable a sync, the previous months data is synced. After that, a sync happens periodically until you disable the checkbox. You can only enable a replica sync:
On cluster environment where each node has one replica.
If you have admin privileges.
On a management node. Any changes made in the management node are reflected in non-management nodes.
Before you begin: Ensure all ESM and ERC devices in your environment are running.
From the Trellix ESM dashboard, click
and select → .Select the checkbox Enable ESM Replica Sync, and in the pop-up window select Yes.
The Initiated Enabling of Replica Sync pop-up window appears. It may take several minutes to perform the sync. Once the sync is complete, it can take over 30 minutes for the dashboard widgets to update.
(Optional) To stop the sync happening periodically after the initial sync, deselect the Enable ESM Replica Sync checkbox.
.png)
.png)
.png)