The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Reset a Trellix SIEM appliance

Prev Next

Reset a Trellix SIEM appliance to factory defaults.

Causes for a reset:

  • Unrecoverable disk corruption

  • Downgrading to an older device version

  • Preparing for a redeployment

  • Changing the FIPS compliance mode

Important

Do not try to reset your device without consulting Trellix Support. A Trellix Support Engineer can help you determine the nature of the fault, and if a reset is needed.

This process deletes all event data on the device.

  1. Prepare the USB drive.

    1. Format the drive with NTFS.

    2. Download the Yumi Multiboot tool and not the UEFI edition.

    3. From the Yumi tool, select the USB drive and the image file.

    4. Click Create and wait for the setup to complete.

    5. (Optional) To add additional image files, click Next.

  2. Use the USB drive.

    1. Insert the USB drive into a USB slot on the SIEM device.

    2. On the BIOS screen, press F6 to trigger the boot menu.

    3. Select the USB drive.

      The install prompt appears.

    4. Enter <device name>-usb.

      Where <device name> is the name of the device.

      Important

      Make sure that you enter -usb even if the prompt asks you to press Enter.

    5. Once the ISO file is copied, remove the USB from the device.

    6. Reboot the machine.