Balabit - Archive/cleanup policies (site 1)
Balabit SCB Solution · Config document · referenced from Backup, archive and retention
noteThe design's chapter 4.5.2 gives the third archive a start time of 07:00 and heads its table "for PARTNER1 connections" although the export is
scb_partner2_archive. The as-built table below says PARTNER2-ARCHIVE at 06:00, the same minute as PARTNER1-ARCHIVE. Its prose also describes the directory structure as "Connection Date/Protocol/Connection/", while every table says "Archive date / Protocol / Connection".The three archive/cleanup policies of the site 1 cluster, one per company. Each night each policy moves the audit trails older than 90 days from the appliance to its own NFS export and deletes them locally.
| Item | Value |
|---|---|
| Where | SCB web interface, Policies > Backup & Archive/Cleanup, section Archive/Cleanup policies |
| Cluster | dc1-s-xblb001, the site 1 HA pair dc1-a-ablb001 and dc1-b-ablb001 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.4.2 |
| Used by | The connections: RDP connections, SSH connections |
| Not in it | An archive policy for partner 3, anything that ever deletes from the exports |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.2 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / NAME = ORG-ARCHIVE Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / START TIME = 04:00 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_org_archive Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / RETENTION TIME IN DAYS = 90 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / NAME = PARTNER1-ARCHIVE Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / START TIME = 06:00 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_partner1_archive Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / RETENTION TIME IN DAYS = 90 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / NAME = PARTNER2-ARCHIVE Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / START TIME = 06:00 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_partner2_archive Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / RETENTION TIME IN DAYS = 90 Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes
| Field | What it means |
|---|---|
| SHARE | Called EXPORT on the backup policy page and SHARE here; the same kind of value, volume and qtree on DC1-S-VCVSM001 |
| PATH TEMPLATE | The directory tree created under the export: one directory per archive date, under it one per protocol, under that one per connection |
| RETENTION TIME IN DAYS = 90 | Audit trails older than 90 days are archived to the export and removed from the SCB. The design's "Audit trails cleanup" section states the same 90 days |
| START TIME | 04:00 for the organisation, 06:00 for both partners; nothing runs at 05:00 |
Nothing in the policy limits how long files stay on the NetApp. The 90 days are how long a trail stays on the appliance itself; what happens on the export afterwards was left to the storage side, and my notes keep the retention question as an open TODO.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| PATH TEMPLATE = Archive date / Protocol / Connection | SPS 9.0 offers five templates: "Protocol/Connection/Archive Date/", "Archive Date/Connection/Protocol/", "Connection Date/Protocol/Connection/", "Archive Date/" and "Connection Date/". The as-built order is not among them, and the SCB 5 list had only the first two. The design's prose, "Connection Date/Protocol/Connection/", matches a template of 9.0 |
| RETENTION TIME IN DAYS = 90 | The option ("delete data from SPS after") and the cleanup of the connection database remain |
| Indexing on, archiving after 90 days | If trails are indexed, the index is archived every 30 days, so up to 30 days of index can be lost |
So the path template as written in my design is doubtful: it matches no template in either list, and I cannot tell from the documents which of the offered ones was really selected.