Balabit - Backup and archive policies in config.xml (site 2)
Balabit SCB Solution · Config document · referenced from Backup, archive and retention
The <backup_archive> element of the exported configuration of the site 2 cluster: five backup policies and four archive/cleanup policies, all over NFS to the site 2 NetApp SVM. It is the only place where the backup and archive settings of an SCB exist as the appliance itself wrote them.
| Item | Value |
|---|---|
| File | config.xml, the configuration export inside a support bundle |
| Cluster | dc2-s-xblb001, the site 2 HA pair |
| Taken | 2018-09-17, firmware 5.0.6 |
| Element | <backup_archive>, child of <xcb>, complete |
| Anonymization | Object ids shortened to id026 … id034; addresses and names follow the anonymized plan of this write-up; the element held no secret |
| Site 2 design | None exists; this file is the only record of these policies |
The file
<backup_archive> <backups> <backup id="id026" name="SYSTEM-BACKUP" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_system_backup</nfs_path> </target> <start_times> <start_time>00:00</start_time> </start_times> <notification_send_filelist>yes</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> </backup> <backup id="id027" name="ORG-BACKUP" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_org_backup</nfs_path> </target> <start_times> <start_time>01:00</start_time> </start_times> <notification_send_filelist>yes</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> </backup> <backup id="id028" name="PARTNER1-BACKUP" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner1_backup</nfs_path> </target> <start_times> <start_time>02:00</start_time> </start_times> <notification_send_filelist>yes</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> </backup> <backup id="id029" name="PARTNER2-BACKUP" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner2_backup</nfs_path> </target> <start_times> <start_time>03:00</start_time> </start_times> <notification_send_filelist>yes</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> </backup> <backup id="id030" name="PARTNER4-BACKUP" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner4_backup</nfs_path> </target> <start_times> <start_time>04:00</start_time> </start_times> <notification_send_filelist>yes</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> </backup> </backups> <archives> <archive id="id031" name="ORG-ARCHIVE" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_org_archive</nfs_path> </target> <start_times> <start_time>04:30</start_time> </start_times> <archive_days>90</archive_days> <notification_send_filelist>no</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> <template>2</template> </archive> <archive id="id032" name="PARTNER1-ARCHIVE" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner1_archive</nfs_path> </target> <start_times> <start_time>05:00</start_time> </start_times> <archive_days>90</archive_days> <notification_send_filelist>no</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> <template>2</template> </archive> <archive id="id033" name="PARTNER2-ARCHIVE" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner2_archive</nfs_path> </target> <start_times> <start_time>05:30</start_time> </start_times> <archive_days>90</archive_days> <notification_send_filelist>no</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> <template>2</template> </archive> <archive id="id034" name="PARTNER4-ARCHIVE" notification="error"> <target choice="nfs"> <nfs_server>10.12.18.236</nfs_server> <nfs_path>DC2_S_VCVSM001_data/scb_partner4_archive</nfs_path> </target> <start_times> <start_time>06:00</start_time> </start_times> <archive_days>90</archive_days> <notification_send_filelist>no</notification_send_filelist> <notification_file_count_limit>10240</notification_file_count_limit> <template>5</template> </archive> </archives> </backup_archive>
| Element | What it means |
|---|---|
id | The object id. The connections refer to it, for example <backup idref="id028"/> in Connections in config.xml (site 2); <management> refers to id026 as the system backup policy |
notification="error" | Send a notification only on errors, the "SEND NOTIFICATION ON ERRORS ONLY = Yes" of the site 1 design |
<target choice="nfs"> | NFS to the SVM DC2-S-VCVSM001 at 10.12.18.236, the site 2 twin of 10.11.18.236 |
<start_times> | A list; each policy has one start time |
<notification_send_filelist>, <notification_file_count_limit> | Whether the notification lists the files, and up to how many. yes for the backups, no for the archives. The site 1 design does not show these fields |
<archive_days>90</archive_days> | The retention time in days, as in site 1 |
<template> | The path template as a number: 2 for three archives, 5 for PARTNER4-ARCHIVE. My documents do not map the numbers to the templates offered in the web interface, so I cannot say which directory layout partner 4's archive got |
Compared with site 1, nine months after the site 1 design: a fifth backup policy and a fourth archive policy for partner 4, the archives moved to half-hour steps (04:30, 05:00, 05:30, 06:00) so that no two run together, after the backups that end with PARTNER4-BACKUP at 04:00. Policies for partner 2 exist here as well, although the connection summary's partner 2 sheet is empty. There is no partner 3 policy and no policy for the cloud team of partner 1 in this file.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
<target choice="nfs"> | NFS is still offered beside Rsync and SMB/CIFS; the version is detected automatically, up to NFS version 4 |
<nfs_server> as an IPv4 address | Backup targets must still be IPv4 addresses |
<nfs_path> without a node identifier | SPS 9.0 has an option to include the cluster node ID in the path; this element has no such setting |
<template>2</template>, <template>5</template> | SPS 9.0 offers five named templates; my documents give no mapping of the numbers |
<archive_days>90</archive_days> | The retention option remains |
The settings in the table are still documented in SPS 9.0; the documentation does not describe the XML or the numeric templates, and whether the policies survive the upgrade chain or a data migration is not stated.