AlienVault Unified Security Management 5.x Configuration Backup and Restore
USM 5.x Configuration Backup and Restore Copyright 2015 AlienVault, Inc. All rights reserved. The AlienVault Logo, AlienVault, AlienVault Unified Security Management, AlienVault USM, AlienVault Open Threat Exchange, AlienVault OTX, Open Threat Exchange, AlienVault OTX Reputation Monitor, AlienVault OTX Reputation Monitor Alert, AlienVault OSSIM, and OSSIM are trademarks or service marks of AlienVault, Inc. All other registered trademarks, trademarks or service marks are the property of their respective owners. Revision to This Document Date Revision Description April 30, 2015 Original document published for AlienVault USM version 5.0. June 4, 2015 Document updated to correct some typos and added the note on restoring OSSIM on USM. June 4, 2015 USM 5.x Configuration Backup and Restore Page 2 of 7
Contents Contents The Backup Process... 4 Managing Configuration Backups From the Web UI... 4 What Are Included in Configuration Backups... 4 When Are Configuration Backups Run... 5 Where Are Configuration Backups Stored... 5 How Are Configuration Backups Done in a Federated Environment... 5 The Restore Process... 6 June 4, 2015 USM 5.x Configuration Backup and Restore Page 3 of 7
The Backup Process The backup and restore procedures in USM 4.x requires jailbreaking the system and executing backup commands manually. In USM 5.0, this process has been improved. Users can backup and restore system configurations including system profile, network configuration, inventory data, policies, plugins, correlation directives and other basic settings. Backups are managed in the web UI and run automatically each day or as needed. Users can restore a USM system from a backup file via the AlienVault console. The Backup Process Managing Configuration Backups From the Web UI In the web UI, navigate to Configuration > Administration > Backups > Configuration, the configuration backups display in a table format. The columns are System, Date, Backup, Type, Version, Size, and Download. By default, backups are sorted by their timestamps, with the latest one at the top. To look for a backup, use the search box at the upper left hand corner. You can search on system (name or IP address), date, or type. To download the backups and store them locally, locate the backup and click the Download button towards the right. To delete one or more backups, select them by checking the square to the left of each backup, and then click the Delete button above the table towards the right. What Are Included in Configuration Backups System configuration (networking, system profile, USM basic configuration settings) Inventory data Policies Plugins (both default and customized) Correlation directives HIDS configurations Note: Security events and raw logs are NOT included in the backups. June 4, 2015 USM 5.x Configuration Backup and Restore Page 4 of 7
The Backup Process When Are Configuration Backups Run Backups are run at 7:00 am local time every day. They display as "Auto" under the Type column in the web UI. You can also run a backup yourself at any time. To run a backup manually 1. In the web UI, navigate to Configuration > Administration > Backups > Configuration. 2. Click Run Backup Now. A message comes up showing when the last backup was run and asking if you want to continue. 3. Select Yes to start the backup. These backups display as "Manual" under the Type column. When a backup process runs, we first do the following checks to make sure that normal USM operation is not interrupted: There isn't a re-configuration process running. There isn't another instance of backup or restore process running. There is enough disk space to create a configuration backup file. The backup process will not continue if any of the checks fails. To see the error messages in the backup logs, click View Backup Logs on Configuration > Administration > Backups > Configuration. Where Are Configuration Backups Stored Each USM appliance stores its configuration backup files as /var/alienvault/backup/configuration_<hostname>_<timestamp>.tar.gz Backups marked as Auto are rotated daily, and we maintain 10 backups on each appliance based on their timestamp. How Are Configuration Backups Done in a Federated Environment In a federated environment, where you have sensor(s) reporting to a USM Server (child server), which reports to another USM Server (federated server), keep the following in mind: June 4, 2015 USM 5.x Configuration Backup and Restore Page 5 of 7
The Restore Process Each USM Server (both child server and federated server) will only trigger automatic backups of itself and directly connected sensors. In other words, the federated server does not trigger automatic backups to its child servers. The backups are stored per AlienVault appliance. This means that each appliance will store its own backup file. In the web UI, there is a Show Backups for dropdown allowing you to choose which system you want to view. You can select the child server on the federated server, but not vice versa. On the federated server, you can run a manual backup of the child server. To do this, select the child server from the drop-down, and then click Run Backup Now. The Restore Process You can only restore a USM system from a backup file via the AlienVault console. When a restore process runs, we first do the following checks to make sure that the underlying system is ready and compatible: There isn't a re-configuration process running. There isn't another instance of backup or restore process running. The backup profile matches the system profile. In other words, you cannot restore a backup file from a USM Server on a USM Sensor. The version of the backup file is the same as the target system. This means that you cannot restore a USM v5.0 backup on a system that is running USM v4.x. There is enough disk space to restore the configuration backup. Note: You can restore an OSSIM backup on a USM or vice versa, as long as they are on the same version. Before restoring a backup file, you will need to transfer the file to the target system first. To do this, you can use an SFTP client on Windows OS, such as WinSCP; or the scp protocol on Linux-based systems. On the target system, you need to place the file in /var/alienvault/backup/ June 4, 2015 USM 5.x Configuration Backup and Restore Page 6 of 7
The Restore Process To restore the backup file 1. Connect to the AlienVault Console via ssh or putty. The AlienVault Setup menu displays. 2. Select Maintenance & Troubleshooting, click <OK> or press Enter. 3. Select Backups, click <OK> or press Enter. 4. Select Restore configuration backup, click <OK> or press Enter. 5. Select the backup you want to restore, click <OK> or press Enter. A confirmation message displays. 6. Select <Yes> to continue or <No> to abort. The restore process starts. The system restarts automatically once the restore process finishes. If an SSH connection is used to perform the restoration process, and there is an IP address change, the network connection will be dropped. June 4, 2015 USM 5.x Configuration Backup and Restore Page 7 of 7