LINUXOR.SK ... open source notes ...

Balabit - Archive/cleanup policies (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Backup, archive and retention

noteThe design's chapter 4.5.2 gives the third archive a start time of 07:00 and heads its table "for PARTNER1 connections" although the export is scb_partner2_archive. The as-built table below says PARTNER2-ARCHIVE at 06:00, the same minute as PARTNER1-ARCHIVE. Its prose also describes the directory structure as "Connection Date/Protocol/Connection/", while every table says "Archive date / Protocol / Connection".

The three archive/cleanup policies of the site 1 cluster, one per company. Each night each policy moves the audit trails older than 90 days from the appliance to its own NFS export and deletes them locally.

ItemValue
WhereSCB web interface, Policies > Backup & Archive/Cleanup, section Archive/Cleanup policies
Clusterdc1-s-xblb001, the site 1 HA pair dc1-a-ablb001 and dc1-b-ablb001
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.4.2
Used byThe connections: RDP connections, SSH connections
Not in itAn archive policy for partner 3, anything that ever deletes from the exports

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.2

Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / NAME = ORG-ARCHIVE
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / START TIME = 04:00
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_org_archive
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / RETENTION TIME IN DAYS = 90
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > ORG-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes

Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / NAME = PARTNER1-ARCHIVE
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / START TIME = 06:00
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_partner1_archive
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / RETENTION TIME IN DAYS = 90
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER1-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes

Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / NAME = PARTNER2-ARCHIVE
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / START TIME = 06:00
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / SHARE = DC1_S_VCVSM001_data/scb_partner2_archive
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / PATH TEMPLATE = Archive date / Protocol / Connection
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / RETENTION TIME IN DAYS = 90
Policies > Backup & Archive/Cleanup > Archive/Cleanup policies > PARTNER2-ARCHIVE / SEND NOTIFICATION ON ERRORS ONLY = Yes
FieldWhat it means
SHARECalled EXPORT on the backup policy page and SHARE here; the same kind of value, volume and qtree on DC1-S-VCVSM001
PATH TEMPLATEThe directory tree created under the export: one directory per archive date, under it one per protocol, under that one per connection
RETENTION TIME IN DAYS = 90Audit trails older than 90 days are archived to the export and removed from the SCB. The design's "Audit trails cleanup" section states the same 90 days
START TIME04:00 for the organisation, 06:00 for both partners; nothing runs at 05:00

Nothing in the policy limits how long files stay on the NetApp. The 90 days are how long a trail stays on the appliance itself; what happens on the export afterwards was left to the storage side, and my notes keep the retention question as an open TODO.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
PATH TEMPLATE = Archive date / Protocol / ConnectionSPS 9.0 offers five templates: "Protocol/Connection/Archive Date/", "Archive Date/Connection/Protocol/", "Connection Date/Protocol/Connection/", "Archive Date/" and "Connection Date/". The as-built order is not among them, and the SCB 5 list had only the first two. The design's prose, "Connection Date/Protocol/Connection/", matches a template of 9.0
RETENTION TIME IN DAYS = 90The option ("delete data from SPS after") and the cleanup of the connection database remain
Indexing on, archiving after 90 daysIf trails are indexed, the index is archived every 30 days, so up to 30 days of index can be lost

So the path template as written in my design is doubtful: it matches no template in either list, and I cannot tell from the documents which of the offered ones was really selected.

← solutionz