Event storage is also known as the ring buffer. If the xAgents' events database exceeds the storage specified by this setting, the xAgent rebuilds the database. If the database is corrupt and the attempt to rebuild it fails, the database is restarted and a new, empty events database is created. The old events database is backed up as file events.db.bk. You may need assistance from Trellix Technical Support to extract the data contained in the backup.
You can specify the event storage use limit for select host sets in your environment by creating a custom policy in the Web UI to define your exception resource use policy
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
Click Create Custom Policy to go to the Create Policy page.
.png)
Enter a policy name in the Name field and a policy description in the Description field.
Click CATEGORIES to access a list of the policy categories.
Select the Resource Use checkbox and click Apply.
In the Resource Use section, specify the number of megabytes of storage that agents in the selected host sets can use for tasks performed on behalf of the Endpoint Security (HX) server in the Event storage field. Valid values range from 10 to 500 MB.
.png)
Click SAVE.
Toggle the policy Enabled/Disabled switch to Enabled to activate the new policy.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.