cancel
Showing results for 
Search instead for 
Did you mean: 

SIEM Backup

Hi frnds,

Can anyone have some idea on backup process.what is the difference between them.what data are covered in backup and full backup..

Please share your suggestions.

6 Replies
Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 2 of 7

Re: SIEM Backup

Backup Now > ESM Configurations and Settings only, no Data

Full Backup Now > Everything

Highlighted

Re: SIEM Backup

is custom watch list, custom alarms,custom correlation rule,data sources is covered in backup now process..

Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 4 of 7

Re: SIEM Backup

I doubt watchlists, alarms and correlation rules are part of the config backup. That's because McAfee recommend to back those up before the upgrade to 10.x in their release note.

Data sources maybe, but I haven't checked. As a precaution, you should periodically export data source settings, in case ERC experiences hardware issue and require re-image or RMA.

kmc
Level 12
Report Inappropriate Content
Message 5 of 7

Re: SIEM Backup

A standard backup saves all configuration settings, including those for policy, as well as SSH, Network, and SNMP files where as full backup includes device settings (above specified) and the system data.

one thing you need keep in mind that once you initiate full backup SIEM will go offline and it's available only after the completion of the full backup

Re: SIEM Backup

Kmc, Thanks for providing information, but my ask still not full fill that as there is two options for backup 1. Backup Now 2. Full backup now.

So i need to clear it out what thing are covered in 1.Backup Now option as i know that in full backup it will take a back of all.

Please help me to understand this.

kmc
Level 12
Report Inappropriate Content
Message 7 of 7

Re: SIEM Backup

Hi

Normal backup will Backup ESM settings(specified above) and events(if only selected), flows (if only selected), and logs (if only selected)

To be clear:Collects all users, reports, dashboards, Receiver data sources, templates, alarms, filters, watchlists, and user created content.

Where as Full Backup will backup: ESM settings, Events Data, flow Data, Event Log data and settings of the ESM, ERC, DEM, ADM, and ACE devices if configured.

Reference: McAfee Corporate KB - When to use a Full System backup, a Settings Only backup, and an Incremental b...

Note: If you are doing full backup you should store it in remote.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community