SSIM Backup & Restore Procedures:
These files should be backed up from Symantec Security Information Manager.
And after Backup these files should be moved to backup Tape libraries for storage.
- DB2 Backup
- LDAP Backup
- Full Everntarchive Backup
DB2 & LDAP Backup Process though Web console:
The below mentioned backups needs to be taken from Web console of SSIM System (Archiver)
1. Open the browser and open URL of SSIM server e.g. https://10.1.1.1 and login through valid username and password
2. After login click on Maintanance -> backup & restore option as shown below
3. Need to take backup of two components LDAP backup and Database Backup
4. Click on LDAP backup and enter the root user’s password and press backup LDAP to initiate LDAP Backup
5. Click on Database bckup Button to start database backup
6. After completing LDAP backup and Database backup see the status of Backup job in Job status window which appears below the backup option as shown below or from Monitor -> SSIM-> Database status
After Successful backup you will see message like Below
Status: Finished Exit result: OK
Start time: XX/XX/XXXX X:XX:XX AM End time: XX/XX/XXXX X:XX:XX AM
Full Event Archive data can be directly backed up to any offline TAPE libraries.
Restore LDAP, DB and Event Archive data from SSIM backup data
Restoring SSIM backup:
• Restore DB2
• Restore LDAP
• Resotre eventarchive
Transfer required ldap, db and events archive backup data to an off box system. Once required data is available on network, same can to copied on SSIM appliances on specific path location for data restore.
LDAP & DB data backup restore steps
a. LDAP, DB Data backup can be transferred through WINSCP or FTP(required to open on temporarily basis from the specific IP)
b. Copy file (ldifbackup) at /dbsesa/backup/ldap/
c. Copy files of DB2 SESA of required dates at /dbsesa/backup.
d. Open respective SSIM Appliance console through https and click on restore ldap for ldap data restore and click database restore for db data restore.
II. Event Archive data restore
- Create required folder under /eventarchive/default/ for the period you want to restore data.
- Transfer all required files from an off box Server (where data is available on network) location through WINSCP or FTP (required to open on temporarily basis from the specific IP) on SSIM Archive box under folder created in step a.
- Once required events archive data is restored on SSIM Archive then same can be accessed through SSIM console using queries as per the requirement.