The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Replace failed Receivers

Prev Next

If a secondary receiver has an unresolved health problem, you might need to replace it. When you receive the new receiver, install it. When the IP addresses are set and the cables are plugged in, you can restore the receiver into the high availability cluster.

  1. On the system navigation tree, select Receiver Properties for the high availability receiver, then click Receiver ConfigurationInterface.

  2. Click the HA Receiver tab, then verify that Setup High Availability is selected.

  3. Verify that the IP addresses are correct, then click Reinitialize Secondary.

    If a high availability receiver goes down for any reason, the writing of data sources, global settings, aggregation settings, and others appears to fail and an SSH error appears. The settings roll out to the receiver that is still functioning, but an error appears because it can't sync with the receiver that is down. Policy, but, does not roll out.

  4. If the service of the secondary receiver is offline, click High AvailabilityReturn To ServiceSecondary to bring it online.

  5. Do one of the following:

    • Wait to roll out policy until a secondary receiver is available and synced.

    • Remove the Receiver from HA mode, which causes two to five minutes of down time for the HA cluster during which no events are gathered.