The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Store data on a redundant Enterprise Log Manager (ELM)

Prev Next

Add a standby Trellix Enterprise Security Manager - Enterprise Log Manager to reduce the risk of data loss if the primary ELM fails.

  • Your system must include a standalone ELM (not an all-in-one).

  • Configure a standby ELM but don't add it to the device tree.

  • Make sure that there is no data on the standby ELM. Contact Technical Support if you need to perform a factory reset.

  1. On the system navigation tree, click the ELM, then click the Properties icon GUID-F191D568-8B93-4D2C-9BFC-F1342FC407BD-low.png.

  2. On the ELM Properties page, click ELM Redundancy, then click Enable.

  3. Type the IP address and password for the standby ELM, then click OK.

  4. On the ELM Properties page, click Storage Pools, and verify that the Active tab is selected.

  5. Add storage devices to the active ELM.

  6. Click the Standby tab, then add storage devices that have enough combined space to match the storage on the active ELM.

  7. Add one or more storage pools to each ELM.

  8. Maintain the redundant relationship.

    Option

    Definition

    Available only when ELM redundancy is not enabled.

    Enable

    Click, then add standby ELM data to activate ELM redundancy.

    Available only when ELM redundancy is enabled.

    Remove

    Click to disable redundancy on the ELM.

    Switch ELMs

    Click to switch the ELMs so the standby ELM becomes the primary ELM. The system associates all logging devices to it. Logging and configuration actions are locked during the switch-over process.

    Suspend

    Click to suspend communication with the standby ELM if it is experiencing problems. All communication stops and error notifications for redundancy are masked. When you bring the standby ELM back up, click Return to Service.

    Status

    Click to view details about the state of data synchronization between the active and standby ELM.

    Return to service

    Click to return a repaired or replaced standby ELM to service. If the system brings the ELM back up and detects no changes to the configuration files, redundancy continues as before. If the system does detect differences, the redundancy process continues for the storage pools without problems, and you are informed that one or more pools are out of configuration. Fix these pools manually.

    If you replace or reconfigure the standby ELM, the system detects it and prompts you to rekey it. The active ELM then syncs all configuration files to the standby ELM and the redundancy process continues as before.

The configuration on both ELMs is synchronized and the standby ELM maintains the synchronization of data between both devices.