Appliance setup
Inspect packaging and appliance
- Inspect the packaging for damage.
- After unpacking the product, inspect the appliance for damage.
Note: If there is any sign of damage, mishandling, or tampering contact Trellix Support immediately for instructions, and do not install the product.
Install rail set and chassis (Generation 6)
- Install the inner rails on the chassis.
- Locate the inner rails and attach them to the sides of the chassis.
- Slide the inner rails forward until they click into place.
- Verify the inner rails are securely attached.
- Install the outer rails in the rack.
- Align the outer rails with the rack posts.
- Secure the outer rails to the rack posts using the provided screws.
- Verify the outer rails are level and secure.
- Install the chassis in the rack.
- With two people, lift the chassis and align the inner rails with the outer rails.
- Slide the chassis into the rack until it is fully seated.
- Secure the chassis to the rack using the captive screws on the front panel.
- Connect the cables as described in the network ports section.
Caution: Always load the rack from the bottom up to prevent the rack from tipping.
Caution: At least two people are required to lift and install the chassis into the rack.
Install rail set and chassis (Generation 5.5/5)
- Install the rails.
- Attach the front brackets to the front rack posts.
- Attach the rear brackets to the rear rack posts.
- Slide the intermediate rail member into the outer rail.
- Lock the ball retainer on each intermediate rail member.
- Verify all rail components are securely attached.
- Install the chassis.
- With two people, lift the chassis.
- Align the chassis with the inner rails.
- Slide the chassis into the rack.
- Verify the chassis is fully seated.
- Secure the chassis to the rack.
- Verify all connections are secure.
Caution: Make sure that the ball retainer is locked on each intermediate rail member.
Remove the chassis
- Power off the appliance and disconnect all cables.
- Remove the captive screws securing the chassis to the rack front panel.
- With two people, slide the chassis out of the rack.
- Place the chassis on a stable flat surface.
Generation 6 Hardware - Network ports
Caution: Do not connect cables to ports not labeled for a specific purpose.
Trellix ESM
- Power supply
- VGA video
- USB port
- COM port
Port connections
| Slot numbers | 4-port systems | 8-port systems (add-on only) | Connections |
|---|
| 1 | Port 1 | Port 1 | Management 1 |
| 2 | Port 2 | Port 2 | Management 2 |
| 3 | Port 3 | Port 3 | HA |
| 4 | Port 4 | Port 4 | Data |
| 5 | BMC/RMM | BMC/RMM | BMC/RMM |
| 6 | — | Port 5 | Data |
| 7 | — | Port 6 | Data |
| 8 | — | Port 7 | Data |
Note: The BMC/RMM port (port 5) is used for setup and troubleshooting.
| Slot numbers | 4-port systems | 8-port systems (add-on only) | Connections |
|---|
| 1 | Port 1 | Port 1 | Management 1 |
| 2 | Port 2 | Port 2 | Management 2 |
| 3 | Port 3 | Port 3 | HA |
| 4 | Port 4 | Port 4 | Data |
| 5 | BMC/RMM | BMC/RMM | BMC/RMM |
| 6 | — | Port 5 | Data |
| 7 | — | Port 6 | Data |
| 8 | — | Port 7 | Data |
HA connections
- Connect the HA cable from the HA port on the primary appliance.
- Connect the other end of the HA cable to the HA port on the secondary appliance.
- Verify the HA link is established in the management interface.
Generation 5.5 Hardware - Network ports
Caution: Do not connect cables to ports not labeled for a specific purpose.
Trellix ESM
- Management 1
- Management 2
- VGA video
- Data (not used)
- MGMT
1U chassis
Note: For 1U chassis, you must use the VGA port for monitor as the DisplayPort is not supported.
| Slot | Ports and connectors | Additional information | For Non-HA | For HA |
|---|
| 1 | Management 1 | — | Yes | Yes |
| 2 | Management 2 | — | Optional | Optional |
| 3 | HA | — | No | Yes |
| 4 | Data | — | Yes | Yes |
| 5 | Data | — | Optional | Optional |
| 6 | Data | — | Optional | Optional |
| 7 | Data | — | Optional | Optional |
| 8 | IPMI | Out-of-band management | Optional | Optional |
| Slot | Ports and connectors | Additional information | For Non-HA | For HA |
|---|
| 1 | Management 1 | — | Yes | Yes |
| 2 | Management 2 | — | Optional | Optional |
| 3 | HA | — | No | Yes |
| 4 | Data | — | Yes | Yes |
| 5 | Data | — | Optional | Optional |
| 6 | Data | — | Optional | Optional |
| 7 | Data | — | Optional | Optional |
| 8 | IPMI | Out-of-band management | Optional | Optional |
1U chassis HA connections
- Connect the HA cable to the HA port on the primary ESM.
- Connect the other end of the HA cable to the HA port on the secondary ESM.
- Verify the HA link LED is active.
2U chassis
| Slot | Ports and connectors | Additional information | For Non-HA | For HA |
|---|
| 1 | Management 1 | — | Yes | Yes |
| 2 | Management 2 | — | Optional | Optional |
| 3 | HA | — | No | Yes |
| 4 | Data | — | Yes | Yes |
| 5 | Data | — | Optional | Optional |
| 6 | Data | — | Optional | Optional |
| 7 | Data | — | Optional | Optional |
| 8 | IPMI | Out-of-band management | Optional | Optional |
2U chassis HA connections
- Connect HA cable from primary ESM HA port.
- Connect HA cable to secondary ESM HA port.
- Connect management cable from primary ESM Management 1 port.
- Connect management cable to secondary ESM Management 1 port.
- Connect data cables to the appropriate data ports.
- Connect the IPMI cable if out-of-band management is required.
- Connect power cables to both power supplies.
- Verify all connections before powering on.
Generation 5 Hardware - Network ports
Caution: Do not connect cables to ports not labeled for a specific purpose.
Trellix ESM
Note: Port assignments are the same on 1U and 2U chassis.
- Management 1
- Management 2
- VGA video
- Data (not used)
- IPMI
1U chassis
| Slot | Ports and connectors | Additional information | For Non-HA | For HA |
|---|
| 1 | Management 1 | — | Yes | Yes |
| 2 | Management 2 | — | Optional | Optional |
| 3 | HA | — | No | Yes |
| 4 | Data | — | Yes | Yes |
| 5 | Data | — | Optional | Optional |
| 6 | Data | — | Optional | Optional |
| 7 | Data | — | Optional | Optional |
| 8 | IPMI | Out-of-band management | Optional | Optional |
1U chassis HA connections
- Connect the HA cable to the HA port on the primary ESM.
- Connect the other end of the HA cable to the HA port on the secondary ESM.
- Connect management cables.
- Connect data cables.
- Connect IPMI cables if required.
- Verify all connections before powering on.
2U chassis
| Slot | Ports and connectors | Additional information | For Non-HA | For HA |
|---|
| 1 | Management 1 | — | Yes | Yes |
| 2 | Management 2 | — | Optional | Optional |
| 3 | HA | — | No | Yes |
| 4 | Data | — | Yes | Yes |
| 5 | Data | — | Optional | Optional |
| 6 | Data | — | Optional | Optional |
| 7 | Data | — | Optional | Optional |
| 8 | IPMI | Out-of-band management | Optional | Optional |
2U chassis HA connections
- Connect the HA cable to the HA port on the primary ESM.
- Connect the other end of the HA cable to the HA port on the secondary ESM.
- Connect management cables.
- Connect data cables.
- Connect IPMI cables if required.
- Verify all connections before powering on.
Connect power and start appliances
- Connect the power cords to the power supplies on the rear of the appliance.
- Connect the power cords to the power source.
- Press the power button to start the appliance.
Important: Connecting redundant power cords and power modules operating at normal conditions balances the load share, resulting in a more reliable power system.
Generation 6 LEDs
Power supply status LED
| Color | State | Status |
|---|
| Green | Solid | Power supply is operating normally |
| Amber | Solid | Power supply has failed |
| Amber | Blinking | Power supply warning condition |
| Off | — | No power connected or power supply failure |
| Green/Amber | Alternating | Firmware update in progress |
External RJ45 NIC Port LED
| LED Color | Description |
|---|
| Green | Link established at 1 Gbps |
| Amber | Link established at 100 Mbps or 10 Mbps |
System Status LED
| Color | State | Description |
|---|
| Green | Solid | System is on and operating normally |
| Green | Blinking (1 Hz) | System is degraded |
| Green | Blinking (4 Hz) | System POST in progress |
| Amber | Solid | Non-recoverable condition |
| Amber | Blinking (1 Hz) | System is in a degraded state |
| Amber | Blinking (4 Hz) | System is in a critical state |
| Off | — | System is off |
| Blue | Solid | System is identified (UID on) |
| Blue | Blinking | Remote console session is active |
| Red | Solid | System failure |
Drive Activity and Status LED
| Color | State | Status |
|---|
| Green | Blinking | Drive activity |
| Amber | Solid | Drive failure |
| Off | — | No drive installed or drive not in use |
| Color | Condition | Drive Type | Behavior |
|---|
| Green | Normal operation | All | Blinking with drive activity |
| Amber | Drive rebuild | HDD/SSD | Blinking at 4 Hz |
| Amber | Drive failure | All | Solid |
| Amber/Green | Drive predicted failure | All | Alternating |
| Green | Identify mode | All | Blinking at 4 Hz |
| Off | No drive | — | Off |
| Off | Drive not configured | All | Off |
| Green | Drive online | All | Solid |
| LED | State | Description |
|---|
| Green | Solid | System is powered on |
| Green | Blinking (1 Hz) | System is in standby |
| Off | — | System is off |
| Amber | Solid | System failure |
BMC Boot or Reset Status LED indicators
| BMC Boot or Reset State | UID LED | State | Status LED |
|---|
| BMC is booting | Blue | Solid | Amber blinking |
| BMC boot complete | Off | — | Matches system status |
| BMC reset in progress | Blue | Blinking | Amber blinking |
Generation 5 LEDs
Power supply status LED
| Power Supply Condition | LED State |
|---|
| Output on and OK | Green solid |
| No input power | Off |
| Power supply warning | Amber blinking |
| Power supply failure | Amber solid |
| Firmware update | Green/Amber alternating |
| AC input detected, output off | Green blinking (1 Hz) |
| Power supply not installed | Off |
External RJ45 NIC Port LED
| LED | Color | LED State | NIC State |
|---|
| Activity | Green | Blinking | Network activity |
| Activity | Off | Solid | No network activity |
| Link | Green | Solid | 1 Gbps link |
| Link | Amber | Solid | 100 Mbps link |
| Link | Off | — | No link |
| Link | Green | Blinking | 10 Mbps link |
System Status LED
| Color | State | Criticality | Description |
|---|
| Green | Solid | Normal | System is on and operating normally |
| Green | Blinking | Normal | System is in standby |
| Amber | Solid | Critical | System failure or critical event |
| Amber | Blinking | Non-critical | System warning event |
| Off | — | — | System is off or no power |
Drive Activity and Status LED
| Color | State | Status |
|---|
| Amber | Solid | Drive failure |
| Amber | Blinking (4 Hz) | Drive rebuild |
| Off | — | No drive or drive not in use |
| Color | Condition | Drive Type | Behavior |
|---|
| Green | Normal operation | All | Blinking with drive activity |
| Amber | Drive rebuild | HDD/SSD | Blinking at 4 Hz |
| Amber | Drive failure | All | Solid |
| Amber/Green | Predicted failure | All | Alternating |
| Green | Identify mode | All | Blinking at 4 Hz |
| Off | No drive | — | Off |
| Off | Not configured | All | Off |
| Green | Drive online | All | Solid |
| State | Power Mode | LED | Description |
|---|
| On | Full power | Green solid | System is powered on |
| Standby | Standby | Green blinking | System is in standby mode |
| Off | Off | Off | System is powered off |
| Failure | — | Amber solid | System failure |
BMC Boot or Reset Status LED indicators
| BMC Boot or Reset State | ID LED | Status LED | Description |
|---|
| BMC is booting | Blue solid | Amber blinking | BMC is initializing |
| BMC boot complete | Off | Matches system | Normal operation |
| BMC reset | Blue blinking | Amber blinking | BMC is resetting |
| BMC firmware update | Blue solid | Amber solid | Firmware update in progress |
| BMC failure | Blue blinking | Amber solid | BMC failed to boot |
Install Trellix Direct Attached Storage (DAS) appliance
- Power off the Trellix ESM appliance.
- Mount the DAS appliance in the rack below the ESM appliance.
- Connect the Mini SAS HD cable from port 1 of the ESM appliance to port 1 of the DAS appliance.
- Connect the power cable to the DAS appliance.
- Connect the power cable to the power source.
- Power on the DAS appliance.
- Power on the ESM appliance.
- Log in to the ESM management interface.
- Verify that the DAS appliance is recognized by the ESM.
Note: Ensure the cable is attached from Mini SAS HD port 1 of Trellix ESM appliance to Mini SAS HD port 1 of DAS.
Caution: Do not plug into any other ports unless directed by Trellix support.
Install qLogic 2460 or 2562 Storage Area Network (SAN) adapters
- Verify the system is powered off before installing the adapter.
- Ensure you have the correct adapter model for your system.
- Power off the ESM appliance.
- Install the qLogic adapter into the appropriate PCIe slot.
- Secure the adapter with the retaining screw.
- Connect the fiber cables to the adapter ports.
- Power on the appliance and verify the adapter is recognized.
Reset a Trellix SIEM appliance
- Hardware failure requiring replacement
- Forgotten administrator password
- Corrupted operating system
- Returning a device to factory defaults
Important: Do not try to reset your device without consulting Trellix Support. This process deletes all event data on the device.
- Insert the recovery USB drive into the appliance USB port.
- Power on the appliance.
- Press F11 at the boot screen to enter the boot menu.
- Select the USB drive as the boot device.
- At the prompt, type
-usb and press Enter.
- Follow the on-screen instructions to complete the reset.
- Remove the USB drive when prompted.
- After the reset completes, the appliance restarts automatically.
- Wait for the appliance to fully boot.
- Log in using the default credentials.
- Reconfigure the appliance as needed.
- Restore data from backup if available.
- Verify the appliance is operating normally.
- Contact Trellix Support to confirm the reset was successful.
Important: Make sure that you enter -usb even if the prompt asks you to press Enter.
Replace a Trellix SIEM appliance
- Back up all data and configuration from the existing appliance.
- Power off the existing appliance and disconnect all cables.
- Remove the existing appliance from the rack.
Note: For some types of rails, you might need to remove a stud from the side of the chassis.
- Install the new appliance in the rack.
- Connect all cables to the new appliance.
- Power on the new appliance and restore the configuration from backup.
Replace Trellix Direct Attached Storage (DAS) appliance
- Back up all data from the DAS appliance.
- Power off the ESM appliance.
- Power off the DAS appliance.
- Disconnect all cables from the DAS appliance.
- Remove the DAS appliance from the rack.
- Install the new DAS appliance in the rack.
- Connect all cables to the new DAS appliance.
- Power on the DAS appliance.
- Power on the ESM appliance and verify the new DAS is recognized.
Note: Ensure the Mini SAS HD cable is connected from port 1 of the ESM to port 1 of the replacement DAS.
Caution: Do not connect cables to ports not intended for the DAS connection.
- Log in to the HA Receiver management interface.
- Navigate to the IPMI configuration section.
- Select either DHCP or Manual configuration.
- Configure the IPMI interface settings.
| Setting | DHCP | Manual |
|---|
| IP Address | Assigned automatically | Enter static IP address |
| Subnet Mask | Assigned automatically | Enter subnet mask |
Tip: Configure both interfaces to check the functioning interface.
Change Password on the HA receiver
- Connect to the HA Receiver via SSH or console.
- Run the following command to list users:
ERCHA2-ERC-2650 ~ # ipmitool user list 3
- Change the password for the appropriate user.
| ID | Name | Callin | Link Auth | IPMI Msg | Channel Priv Limit |
|---|
| 1 | anonymous | false | false | false | NO ACCESS |
| 2 | root | false | true | true | ADMINISTRATOR |
| 3 | admin | false | true | true | ADMINISTRATOR |
| 4 | (empty) | false | false | false | NO ACCESS |
| 5 | (empty) | false | false | false | NO ACCESS |
- Log in to the appliance console.
- Access the terminal configuration menu.
- Select Network Configuration.
- Enter the IP address, subnet mask, and default gateway.
- Enter the DNS server addresses.
- Save the configuration.
- Verify network connectivity.
Important: The terminal menu doesn't prompt you to save changes when exiting. Save your changes before exiting or you'll lose your work.
Update the BIOS on Trellix SIEM Gen5.5 2U appliances
Important: Make sure that you log in using the administrator password to remove the BIOS password from the appliance.
- Download the BIOS update file from the Trellix Support portal.
- Copy the BIOS update file to the appliance.
- Apply the BIOS update.
- Log in to the appliance as root.
- Navigate to the directory containing the BIOS update files.
- Verify the files are present at the root level.
- Run the BIOS update script.
- Wait for the update to complete.
- Do not interrupt the update process.
- Note any messages displayed during the update.
- Restart the appliance to apply the BIOS update.
- Initiate a system restart.
- Enter the BIOS setup during POST if required.
- Verify the new BIOS version is shown.
- Configure BIOS settings as needed.
- Save and exit the BIOS setup.
- Wait for the system to boot completely.
- Verify the appliance is operating normally after the update.
Important: Make sure that the BIOS update files are at the root level before proceeding.
Appliance certifications and specifications
| Certification | Trellix 1U | Trellix 2U or 3U |
|---|
| Electromagnetic emissions/immunity | FCC, CE, VCCI, KCC, BSMI, RCM | FCC, CE, VCCI, KCC, BSMI, RCM |
| Safety | UL, CB, TUV, CE, BIS, KC | UL, CB, TUV, CE, BIS, KC |
DAS
| Certification | Value |
|---|
| Electromagnetic emissions/immunity | FCC, CE, VCCI, KCC, BSMI, RCM |
| Safety | UL, CB, TUV, CE, BIS, KC |
| RoHS | Compliant |
| Energy Star | Not applicable |
| Specification | DAS-120 | DAS-250 |
|---|
| Form factor | 2U rack | 2U rack |
| Drive bays | 12 x 3.5" | 25 x 2.5" |
| Interface | Mini SAS HD | Mini SAS HD |
| Operating temperature | 10–35°C | 10–35°C |
| Shipping temperature | -40–60°C | -40–60°C |
| Operating humidity | 20–80% RH non-condensing | 20–80% RH non-condensing |
| Power supply | Redundant | Redundant |
| Dimensions (H x W x D) | 3.5" x 17.2" x 21.5" | 3.5" x 17.2" x 21.5" |
| Weight | Contact Trellix Support | Contact Trellix Support |
| Parameter | Limits |
|---|
| Operating temperature | 10–35°C (50–95°F) |
| Shipping temperature | -40–60°C (-40–140°F) |
| Operating altitude | 0–3048 m (0–10000 ft) |
| Shipping altitude | 0–12192 m (0–40000 ft) |
| Operating humidity | 8–90% RH non-condensing |
| Shipping humidity | 5–95% RH non-condensing |
| Operating shock | 6G/11ms half sine |
| Unpackaged shock | 15G/11ms half sine |
| Packaged shock | Per ISTA 2A |
| Packaged vibration | Per ISTA 2A |
| AC voltage | 100–240V |
| Parameter | Limits |
|---|
| Operating temperature | 10–35°C (50–95°F) |
| Shipping temperature | -40–60°C (-40–140°F) |
| Operating altitude | 0–3048 m (0–10000 ft) |
| Shipping humidity | 5–95% RH non-condensing |
| Operating shock | 6G/11ms half sine |
| Unpackaged shock | 15G/11ms half sine |
| Packaged shock | Per ISTA 2A |
| Packaged vibration | Per ISTA 2A |
| AC voltage | 100–240V |
| AC frequency | 50–60 Hz |
| Source interrupt | 20ms at 100V |
| Surge | Per ISTA 2A |