Escolar Documentos
Profissional Documentos
Cultura Documentos
The following Backup and restore documentation for ESM 6.5 and ESM 6.8 is based under the following
scenarios and can ONLY be applied under these circumstances.
1. The restoration process needs to be performed on a new ESM server running the same version of
ESM where the backup process was taken.
2. The server needs to be a brand new server recently installed with no prior archives or resources.
3. The connectors restoration process is not part of this backup as this process only focuses on backing
up resources (except for connectors) and archives so connectors need to be registered again.
4. The server may have a new IP address, hostname and Certificate and this process can still be
implemented as this scenario is contemplated when ESM wants to be migrated to a new hardware.
5. In case of disaster recovery, the events of the current day or day in course will always be lost as there
is no archive for such events and there is not a specific way to recover such events.
6. The archives are located on the default path which is /opt/arcsight/logger/data/archives and this path
can't be changed for this procedure to work.
7. These steps are applicable only for version 6.5 and 6.8 and cant be implemented on any other ESM
version.
1. Stop the manager service issuing the command /etc/init.d/arcsight_services stop manager
5. Move the file user_sequences.sql generated on previous step to a safe location outside of ESM server.
9. Run the command /etc/init.d/arcsight_services start manager to start the manager service again.
Restoration process.
1. Run the command /etc/init.d/arcsight_services stop manager to stop the manager services.
4. Run the command /etc/init.d/arcsight_services stop logger_servers to stop manager and logger
service
9. Place the archives under the directory /opt/arcsight/logger/data/archives with permissions set to
arcsight:arcsight and maintaining the original file structure.
11. Run the command /etc/init.d/arcsight_services start all to start all the ESM services.
There is another backup/restore procedure which you can implement which is considered a "snapshot"
of ESM, but we can't ensure such process will work as it is not possible to ensure the integrity of the files
is still the appropiate as no new installation is being performed.
Backup procedure.
1. Run the command /etc/init.d/arcsight_services stop all to stop all services.
2. Once the services are stopped, copy the entire /opt/arcsight directory issuing command cp -R
/op/arcsight <DESTINATION> to another server or backup server. Make sure to replace <Destination>
with a different disk on your server or partition. You can also use scp in case you want to make a copy to
another server via the network.
3. Run the command /etc/init.d/arcsight_services start all to start all services again.
Restore procedure.
1. Install a new server or the recovery server with the same OS version the original ESM Server had and
the same settings.
2. Create the arcsight user and arcsight group with the same username and password such user had on
the previous server.