Administration Guides
How to Backup and Restore an Audit Database
Home

How to Backup and Restore an Audit Database

A key advantage to Easy Auditor architecture is using Isilon native features to protect the audit data.   The following sections explains how to backup and restore the Analytics database.

Backup the Audit Database with SnapshotIQ

  1. Create a  scheduled snapshot  of the HDFS root directory that contains the Audit Database directory with Isilon SnapshotIQ . Example:
  2. Recommended schedule daily snapshot at noon 7 days a week, with 30 day retention

Access zone basepath for audit database is  /ifs/data/igls/analyticsdb 

HDFS root directory: /ifs/data/igls/analyticsdb/eca

Audit Database directory: /ifs/data/igls/analyticsdb/eca

  1. If creating a manual snapshot by using the Isilon GUI, do not leave the snapshot name blank.
  1. A  default  snapshot name will be applied automatically  (e.g. “Snapshot: 2017Nov09, 10:59 PM"). That name format is not supported for ECA cluster due to special character support with HDFS.
  2. That name format will prevent the ECA cluster to be brought up.  Provide a normal name for the snapshot. Avoid to use name with the “:” character.
  1. If creating a scheduled snapshot,  also avoid to use the name with the “:” character (e.g. ScheduleName_Duration_%Y-%m-%d_%H:%M).  That name format is not supported for ECA cluster. That name format will prevent the ECA cluster to be brought up.  Provide a name pattern without “:” character for the snapshot.

Note: Please refer to Isilon documentation for creating a snapshot, including to create a SnapRevert domain

Restore the Audit Database with SnapshotIQ

  1. ssh to ECA master node (node 1). Login as ecaadmin
  2. Run command: ecactl cluster down.
  3. Wait until nodes are down
  4. Isilon command:  
    1. NOTE: You need to run snaprevert domain mark job first if not already done.  See screenshot.
    2. isi job jobs start snaprevert --snapid xxxx (verify the correct snapid of the snapshot to revert to)
  5. To verify the snapshot revert job status, Isilon command to list running jobs: isi job jobs list
  6. Once the snapshot revert job has completed
  7. After ECA Cluster VMs are up, then bring up ECA Cluster
  8. ssh to ECA master node (node 1)
  9. Login as ecaadmin
  10. Run command: ecactl cluster up.
  11. NOTE: During cluster up uncommitted transactions are replayed to the database, this can be seen from the HBASE Region server GUI logs http://x.x.x.x:16030  this can take longer to startup the cluster
  12. Sample below
  13. Verify that ECA Cluster is up and audit database status return no error. Command: ecactl db shell
  14. Until the status appears like above, HBASE is not fully operational.
  15. Done

2017-11-10 08:59:52,729 WARN  [main] util.NativeCodeLoader: Unable to load native-hadoop library for your platform... using builtin-java classes where applicable

HBase Shell; enter 'help<RETURN>' for list of supported commands.

Type "exit<RETURN>" to leave the HBase Shell

Version 1.2.6, rUnknown, Mon May 29 02:25:32 CDT 2017

hbase(main):001:0> status

1 active master, 2 backup masters, 3 servers, 0 dead, 2.6667 average load

Copyright Superna LLC