Reset a Trellix SIEM appliance to factory defaults.
Causes for a reset:
Unrecoverable disk corruption
Downgrading to an older device version
Preparing for a redeployment
Changing the FIPS compliance mode
Important
Do not try to reset your device without consulting Trellix Support. A Trellix Support Engineer can help you determine the nature of the fault, and if a reset is needed.
This process deletes all event data on the device.
Prepare the USB drive.
Format the drive with NTFS.
Download the Yumi Multiboot tool and not the UEFI edition.
From the Yumi tool, select the USB drive and the image file.
Click Create and wait for the setup to complete.
(Optional) To add additional image files, click Next.
Use the USB drive.
Insert the USB drive into a USB slot on the SIEM device.
On the BIOS screen, press F6 to trigger the boot menu.
Select the USB drive.
The install prompt appears.
Enter
<device name>-usb.Where
<device name>is the name of the device.Important
Make sure that you enter
-usbeven if the prompt asks you to press Enter.Once the ISO file is copied, remove the USB from the device.
Reboot the machine.