NetBackup™ Web UI Administrator's Guide

Last Published:
Product(s): NetBackup (11.0.0.1)
  1. Section I. About NetBackup
    1. Introducing NetBackup
      1.  
        About NetBackup
      2.  
        NetBackup web UI features
      3.  
        NetBackup documentation
      4. NetBackup administration interfaces
        1.  
          About security certificates for NetBackup hosts
        2.  
          First-time sign in to the NetBackup web UI
        3.  
          Sign in to the NetBackup web UI
        4.  
          Sign out of the NetBackup web UI
      5.  
        Using the NetBackup web UI
      6.  
        Terminology
    2. Administering NetBackup licenses
      1.  
        About NetBackup licenses
      2.  
        Add licenses
      3.  
        View licenses
      4.  
        Renew licenses
      5.  
        Remove licenses
  2. Section II. Monitoring and notifications
    1. Monitoring NetBackup activity
      1.  
        The NetBackup dashboard
      2. Activity monitor
        1.  
          Monitor NetBackup daemons
        2.  
          Monitor NetBackup processes
      3. Job monitoring
        1.  
          Workloads that require a custom RBAC role for specific job permissions
        2.  
          View a job
        3.  
          Expand or collapse rows in the Jobs tab
        4.  
          View the jobs in the List view
        5.  
          View the jobs in the Hierarchy view
        6.  
          Jobs: cancel, suspend, restart, resume, delete
        7.  
          View the logs for a job
        8.  
          Search for or filter jobs in the jobs list
        9.  
          Create a jobs filter
        10.  
          Edit, copy, or delete a jobs filter
        11.  
          Import or export job filters
        12.  
          Collect logs for Cohesity Technical Support
        13.  
          View the status of a redirected restore
        14. Troubleshooting the viewing and managing of jobs
          1.  
            Job actions not available for workload administrators with limited RBAC permissions on assets
    2. Device monitor
      1.  
        About the Device Monitor
      2.  
        About media mount errors
      3. About pending requests and actions
        1.  
          About pending requests for storage units
        2.  
          Resolve a pending request
        3.  
          Resolve a pending action
        4.  
          Resubmit a pending request
        5.  
          Deny a pending request
    3. Notifications
      1. Job notifications
        1. Send email notifications for job failures
          1.  
            Status codes that generate alerts
        2.  
          Send notifications to the backup administrator about failed backups
        3.  
          Send notifications to a host administrator about backups
        4.  
          Configure the nbmail.cmd script on the Windows hosts
      2. NetBackup event notifications
        1.  
          View notifications
        2.  
          Modify or disable NetBackup event notifications in the web UI
        3.  
          NetBackup event types supported with notifications
        4.  
          About configuring automatic notification cleanup tasks
    4. Registering the data collector
      1.  
        About the data collector
      2.  
        Register the data collector with Cohesity Alta View
      3.  
        Renew Cohesity Alta View token
      4.  
        Register the data collector with NetBackup IT Analytics
      5.  
        View and modify the data collector registration
      6.  
        Unregister the data collector
  3. Section III. Configuring hosts
    1. Managing host properties
      1.  
        Overview of host properties
      2.  
        View or edit the host properties of a server or client
      3.  
        Host information and settings in Host properties
      4.  
        Reset a host's attributes
      5.  
        Active Directory properties
      6.  
        Backup pool host properties
      7. Busy file settings properties
        1.  
          Activating the Busy file settings in host properties
      8.  
        Clean up properties
      9.  
        Client name properties
      10. Client attributes properties
        1. General tab of the Client attributes properties
          1.  
            Offline option usage considerations and restrictions
          2.  
            Where deduplication should occur
        2.  
          Connect options tab of the Client attributes properties
        3.  
          Windows open file backup tab of the Client attributes properties
      11. Client settings properties for UNIX clients
        1.  
          VxFS file change log (FCL) for incremental backups property
      12. Client settings properties for Windows clients
        1.  
          How to determine if change journal support is useful in your NetBackup environment
        2.  
          Guidelines for enabling NetBackup change journal support
      13.  
        Cloud Storage properties
      14.  
        Credential access properties
      15. Data Classification properties
        1.  
          Add a data classification
      16. Default job priorities properties
        1.  
          Understanding the job priority setting
      17.  
        Distributed application restore mapping properties
      18. Encryption properties
        1.  
          Additional encryption methods for Windows clients
      19.  
        Enterprise Vault properties
      20.  
        Enterprise Vault hosts properties
      21. Exchange properties
        1.  
          About the Exchange credentials in the client host properties
      22. Exclude list properties
        1.  
          Add an entry to an exclude list
        2.  
          Add an exception to the exclude list
        3. Syntax rules for exclude lists
          1.  
            Example of a Windows client exclude list
          2.  
            Example of a UNIX exclude list
        4.  
          About creating an include list on a UNIX client
        5.  
          Traversing excluded directories
      23. Fibre transport properties
        1.  
          About Linux concurrent FT connections
      24.  
        Firewall properties
      25. General server properties
        1.  
          Forcing restores to use a specific server
      26. Global attributes properties
        1.  
          About constraints on the number of concurrent jobs
        2.  
          Setting up mailx email client
      27. Logging properties
        1.  
          Logging levels
      28.  
        Lotus Notes properties
      29. Media properties
        1.  
          Results when media overwrites are not permitted
        2.  
          Recommended use for Enable SCSI reserve property
      30.  
        Network properties
      31. Network settings properties
        1.  
          Reverse host name lookup property
        2.  
          Use the IP address family property
      32.  
        Nutanix AHV access hosts
      33. Port ranges properties
        1.  
          Registered ports and dynamically-allocated ports
      34. Preferred network properties
        1.  
          Add or edit a Preferred network setting
        2.  
          How NetBackup uses the directives to determine which network to use
        3.  
          Configurations to use IPv6 networks
        4.  
          Configurations to use IPv4 networks
        5.  
          Order of directive processing in the Preferred network properties
        6.  
          bptestnetconn utility to display Preferred network information
        7.  
          Configuration to prohibit using a specified address
        8.  
          Configuration to prefer a specified address
        9.  
          Configuration that restricts NetBackup to one set of addresses
        10.  
          Configuration that limits the addresses, but allows any interfaces
      35.  
        Properties setting in host properties
      36.  
        RHV access hosts properties
      37. Resilient network properties
        1.  
          View the resiliency status of a client
        2.  
          About Resilient jobs
        3.  
          Resilient connection resource usage
        4.  
          Specify resilient connections for clients
      38.  
        Resource limit properties
      39. Restore failover properties
        1.  
          Assigning an alternate media server as a failover restore server
      40. Retention periods properties
        1.  
          Changing a retention period
        2.  
          Determining retention periods for volumes
      41. Scalable Storage properties
        1.  
          Configuring advanced bandwidth throttling settings
        2.  
          Advanced bandwidth throttling settings
      42. Servers properties
        1.  
          Add a server to a servers list
        2.  
          Remove a server from a servers list
        3.  
          Enable inter-node authentication for a NetBackup clustered primary server
        4.  
          Changing the primary server that performs backups and restores for a client
      43. SharePoint properties
        1.  
          Consistency check options for SharePoint Server
      44. SLP settings properties
        1.  
          About batch creation logic in Storage Lifecycle Manager
      45.  
        Throttle bandwidth properties
      46.  
        Timeouts properties
      47.  
        Universal settings properties
      48.  
        UNIX client properties
      49.  
        UNIX Server properties
      50.  
        User account settings properties
      51.  
        VMware access hosts properties
      52.  
        Windows client properties
      53.  
        Configuration options not found in the host properties
      54.  
        About using commands to change the configuration options on UNIX or Linux clients and servers
    2. Managing credentials for workloads and systems that NetBackup accesses
      1.  
        Overview of credential management in NetBackup
      2.  
        Adding credentials in NetBackup
      3.  
        Add a credential for NetBackup Callhome Proxy
      4.  
        Add a credential for an external KMS
      5.  
        Add a credential for Network Data Management Protocol (NDMP)
      6. Add a configuration for an external CMS server
        1.  
          Configure external credentials
        2. Add a credential for CyberArk
          1.  
            Certificate revocation lists for CyberArk server
        3.  
          Edit or delete the configuration for an external CMS server
        4.  
          Troubleshooting the external CMS server issue
      7.  
        Edit or delete a named credential
      8.  
        Edit or delete Network Data Management Protocol (NDMP) credentials in NetBackup
    3. Managing deployment
      1.  
        About the deployment policies utility
      2.  
        Managing the NetBackup Package repository
      3.  
        Update host
      4. Deployment policies
        1.  
          Attributes tab in Deployment management
        2.  
          Hosts tab in Deployment management
        3.  
          Schedules tab in Deployment management
        4.  
          Security options tab in Deployment management
      5.  
        Copy a deployment policy
      6.  
        Manually deploy a deployment policy
      7.  
        Deployment job status
  4. Section IV. Configuring storage
    1. Overview of storage options
      1.  
        About storage configuration
    2. Configuring disk storage
      1.  
        Create a Media Server Deduplication Pool storage server
      2. Integrating MSDP Cloud and CMS
        1.  
          Migrating or updating MSDP Cloud and CMS
      3.  
        Create a Media Server Deduplication Pool (MSDP) storage server for image sharing
      4.  
        Create an AdvancedDisk, OpenStorage (OST), or Cloud Connector storage server
      5.  
        Create an MSDP server for MSDP volume group (MVG)
      6.  
        Create the MVG volume
      7.  
        Edit a storage server
      8. About configuring disk pool storage
        1.  
          Create a disk pool
        2.  
          Edit a disk pool
      9.  
        Share images from an on-premises location to the cloud
      10.  
        Overview of universal shares
      11. About the MSDP object store
        1.  
          Configuring the MSDP object store
        2.  
          Resetting the MSDP object store root user credentials
    3. Managing media servers
      1.  
        Add a media server
      2.  
        Activate or deactivate a media server
      3.  
        Stop or restart the media device manager
      4.  
        About NetBackup server groups
      5.  
        Add a server group
      6.  
        Delete a server group
    4. Configuring storage units
      1.  
        Overview of storage units
      2.  
        About configuring BasicDisk storage
      3.  
        Create a storage unit
      4.  
        Edit storage unit settings
      5.  
        Copy a storage unit
      6.  
        Delete a storage unit
      7.  
        Tape storage unit considerations
      8. Disk storage unit considerations
        1.  
          About the disk storage model
        2.  
          Configure the NetBackup service credentials for CIFS storage and disk storage units
        3.  
          Disk storage units in storage lifecycle policies
        4.  
          Maintain the available disk space on disk storage units
      9.  
        NDMP storage unit considerations
    5. Configuring robots and tape drives
      1.  
        NetBackup robot types
      2.  
        About the device mapping files
      3.  
        Downloading the device mapping files
      4.  
        Prerequisites for configuring robots and drives
      5. About configuring robots and tapes drives in NetBackup
        1.  
          About device discovery
        2.  
          About device serialization
        3. About robot control
          1.  
            Library sharing example
        4.  
          About drive name rules
      6.  
        Configure drives and robots by using the wizard
      7.  
        Configure drive name rules
      8.  
        Update the device configuration by using the wizard
      9.  
        Robot properties and configuration options
      10.  
        Robot control (robot configuration options)
      11. Managing robots
        1.  
          Change the robot control properties of a robot
        2.  
          Delete a robot
      12.  
        Correlating tape drives and SCSI addresses on Windows hosts
      13. Correlating tape drives and device files on UNIX hosts
        1.  
          UNIX device correlation example
      14. Managing tape drives
        1.  
          Change a drive comment
        2.  
          About downed drives
        3.  
          Change a drive operating mode
        4.  
          Change the operating mode for a drive path
        5.  
          Clean a tape drive
        6.  
          Delete a drive
        7.  
          Reset a drive
        8.  
          Reset the mount time of a drive
        9.  
          Set the drive cleaning frequency
        10.  
          View drive details
      15.  
        Verifying the device configuration
      16.  
        About automatic path correction
      17.  
        Enabling automatic path correction
      18.  
        Replacing a device
      19.  
        Updating device firmware
      20.  
        About the NetBackup Device Manager
      21.  
        About external access to NetBackup controlled devices on UNIX
    6. Configuring tape media
      1.  
        About NetBackup tape volumes
      2.  
        About NetBackup volume pools
      3.  
        About NetBackup volume groups
      4.  
        NetBackup media types
      5. About adding volumes
        1.  
          About adding robotic volumes
        2.  
          About adding standalone volumes
        3.  
          Add a volume
        4.  
          Volume properties
      6. Managing volumes
        1.  
          Edit a volume
        2.  
          About moving volumes
        3.  
          Move volumes
        4. About recycling a volume
          1.  
            Recycling a volume and using the existing media ID
          2.  
            Recycling a volume and using a new media ID
        5.  
          About assigning and deassigning volumes
        6.  
          Delete a volume
        7.  
          Changing the media owner of a volume
        8.  
          Changing the volume group assignment
        9.  
          About rules for moving volumes between groups
        10.  
          Rescan and update barcodes
        11.  
          About barcode rules
        12. About injecting and ejecting volumes
          1.  
            Inject volumes into robots
          2.  
            Eject volumes
          3.  
            Media ejection timeout periods
        13.  
          Label a volume
        14.  
          Erase a volume
        15.  
          Freeze or unfreeze a volume
        16.  
          Suspend or unsuspend volumes
      7. Managing volume pools
        1.  
          Add a volume pool
        2.  
          Edit or delete a volume pool
        3.  
          Volume pool properties
      8. Managing volume groups
        1.  
          Delete a volume group
        2.  
          Move a volume group
    7. Inventorying robots
      1.  
        About robot inventory
      2.  
        When to inventory a robot
      3. About showing a robot's contents
        1.  
          About inventory results for API robots
      4.  
        Show the media in a robot
      5.  
        About comparing a robot's contents with the volume configuration
      6.  
        Comparing media in a robot with the volume configuration
      7.  
        About previewing volume configuration changes
      8.  
        Previewing volume configuration changes for a robot
      9.  
        About updating the NetBackup volume configuration
      10.  
        Update the NetBackup volume configuration with a robot's contents
      11.  
        Robot inventory options
      12.  
        Advanced options for robot inventory settings
      13.  
        Configure media ID generation rules
      14.  
        Barcode rules settings
      15.  
        Media ID generation options
      16.  
        Configure media settings
      17.  
        About media type mapping rules
      18. Configure media type mappings
        1.  
          About adding media type mapping entries
        2.  
          Default and allowable media types
    8. Staging backups
      1.  
        About staging backups
      2.  
        About basic disk staging
      3.  
        Create a BasicDisk storage unit with disk staging
      4.  
        Disk staging storage unit size and capacity
      5.  
        Finding potential free space on a BasicDisk disk staging storage unit
      6.  
        Schedule settings for disk staging
    9. Troubleshooting storage configuration
      1.  
        Registering a media server
      2.  
        Storage configuration issues
  5. Section V. Configuring backups
    1. Overview of backups in the NetBackup web UI
      1.  
        Backup methods supported in the NetBackup web UI
      2.  
        Policy vs. protection plan FAQs
      3.  
        Support for NetBackup policies
      4.  
        Supported protection plan types
    2. Managing policies
      1.  
        Add a policy
      2.  
        About the Epic-Large-File policy type
      3.  
        Example policy - Exchange Server DAG backup
      4.  
        Example policy - Sharded MongoDB cluster
      5.  
        Example policy - Epic-Large-File
      6.  
        Edit, copy, or delete a policy
      7.  
        Deactivate or activate a policy
      8.  
        View automanaged policies and SLPs
      9.  
        About automanaged policies or storage lifecycle policies
      10.  
        Perform manual backups
    3. Managing protection plans
      1.  
        Create a protection plan
      2.  
        Customizing protection plans
      3.  
        Edit or delete a protection plan
      4.  
        Subscribe an asset or an asset group to a protection plan
      5.  
        Unsubscribe an asset from a protection plan
      6.  
        View protection plan overrides
      7.  
        Copy a protection plan policy (automanaged policy) to a classic policy
      8.  
        About Backup now
    4. Protecting the NetBackup catalog
      1.  
        About the NetBackup catalog
      2. Catalog backups
        1.  
          The catalog backup process
        2.  
          Prerequisites for backing up the NetBackup catalog
        3.  
          Configuring catalog backups
        4.  
          Backing up NetBackup catalogs manually
        5.  
          Concurrently running catalog backups with other backups
        6.  
          Catalog policy schedule considerations
        7.  
          How catalog incrementals and standard backups interact on UNIX
        8.  
          Determining whether or not a catalog backup succeeded
        9.  
          Strategies that ensure successful NetBackup catalog backups
      3.  
        Disaster recovery emails and the disaster recovery files
      4.  
        Disaster recovery packages
      5.  
        Set the passphrase to encrypt disaster recovery packages
      6.  
        Recovering the catalog
    5. Managing backup images
      1.  
        About the Catalog utility
      2.  
        Catalog utility search criteria and backup image details
      3.  
        Verify backup images
      4.  
        Promote a copy to a primary copy
      5. Duplicate backup images
        1.  
          Multiplexed duplication considerations
        2.  
          Jobs that appear while making multiple copies
      6.  
        Expire backup images
      7. About importing backup images
        1.  
          About importing expired images
        2.  
          Import backup images, Phase I
        3.  
          Import backup images, Phase II
    6. Pausing data protection activity
      1.  
        Pause backups and other activity
      2.  
        Allow the automatic pause of data protection activity
      3.  
        Pause backups and other activity on a client
      4.  
        View paused backups and other paused activities
      5.  
        Resume data protection activity
  6. Section VI. Managing security
    1. Security events and audit logs
      1.  
        View security events and audit logs
      2. About NetBackup auditing
        1.  
          User identity in the audit report
        2.  
          Audit retention period and catalog backups of audit records
        3.  
          Viewing the detailed NetBackup audit report
      3.  
        Send audit events to system logs
      4.  
        Send audit events to log forwarding endpoints
    2. Managing security certificates
      1.  
        About security management and certificates in NetBackup
      2.  
        NetBackup host IDs and host ID-based certificates
      3. Manage NetBackup security certificates
        1.  
          Reissue a NetBackup certificate
        2.  
          Manage NetBackup certificate authorization tokens
      4. Using external security certificates with NetBackup
        1.  
          Configure an external certificate for the NetBackup web server
        2.  
          Remove the external certificate configured for the web server
        3.  
          Update or renew the external certificate for the web server
        4.  
          View external certificate information for the NetBackup hosts in the domain
    3. Managing host mappings
      1.  
        View host security and mapping information
      2.  
        Approve or add mappings for a host that has multiple host names
      3.  
        Example host mappings
      4.  
        Remove mappings for a host that has multiple host names
    4. Minimizing security configuration risk
      1.  
        About security configuration risk
      2.  
        Security settings to be configured to minimize risk
      3.  
        Set the current posture as security baseline
      4.  
        Manage security baseline
      5.  
        Manage security baseline from Alta View UI
    5. Configuring multi-person authorization
      1.  
        About multi-person authorization
      2.  
        Workflow to configure multi-person authorization for NetBackup operations
      3.  
        RBAC roles and permissions for multi-person authorization
      4.  
        Multi-person authorization process with respect to roles
      5.  
        NetBackup operations that need multi-person authorization
      6.  
        Configure multi-person authorization
      7.  
        View multi-person authorization tickets
      8.  
        Manage multi-person authorization tickets
      9.  
        Add exempted users
      10.  
        Schedule expiration and purging of multi-person authorization tickets
      11.  
        Disable multi-person authorization
    6. Managing user sessions
      1.  
        Terminate a NetBackup user session
      2.  
        Unlock a NetBackup user
      3.  
        Configure when idle sessions should time out
      4.  
        Configure the maximum of concurrent user sessions
      5.  
        Configure the maximum of failed sign-in attempts
      6.  
        Display a banner to users when they sign in
    7. Configuring multifactor authentication
      1.  
        About multifactor authentication
      2.  
        Configure multifactor authentication for your user account
      3.  
        Disable multifactor authentication for your user account
      4.  
        Enforce multifactor authentication for all users
      5.  
        Configure multifactor authentication for your user account when it is enforced in the domain
      6.  
        Reset multifactor authentication for a user
    8. Managing the global security settings for the primary server
      1.  
        View the Certificate authority for secure communication
      2.  
        Disable communication with NetBackup 8.0 and earlier hosts
      3.  
        Disable automatic mapping of NetBackup host names
      4.  
        Configure the global data-in-transit encryption setting
      5.  
        About NetBackup certificate deployment security levels
      6.  
        Select a security level for NetBackup certificate deployment
      7.  
        About TLS session resumption
      8.  
        Set a passphrase for disaster recovery
      9.  
        Validate the disaster recovery package passphrase
      10. About trusted primary servers
        1.  
          About the certificate to use to add a trusted primary server
        2.  
          Add a trusted primary server
        3.  
          Remove a trusted primary server
      11.  
        Configure the audit retention period
    9. Using access keys, API keys, and access codes
      1.  
        Access keys
      2. API keys
        1.  
          Add an API key or view API key details (Administrators)
        2.  
          Edit, reissue, or delete an API key (Administrators)
        3.  
          Add an API key or view your API key details
        4.  
          Edit, reissue, or delete your API key
        5.  
          Use an API key with NetBackup REST APIs
      3. Access codes
        1.  
          Request CLI access through web UI authentication
        2.  
          Approve the CLI access request of another user
        3.  
          Edit the settings for command-line access
    10. Configuring authentication options
      1.  
        Sign-in options for the NetBackup web UI
      2. Configure user authentication with smart cards or digital certificates
        1.  
          Configure smart card authentication with a domain
        2.  
          Configure smart card authentication without a domain
        3.  
          Edit the configuration for smart card authentication
        4.  
          Add or delete a CA certificate that is used for smart card authentication
        5.  
          Disable or temporarily disable smart card authentication
      3.  
        About single sign-on (SSO) configuration
      4. Configure NetBackup for single sign-on (SSO)
        1.  
          Configure the SAML KeyStore
        2.  
          Configure the SAML keystore and add and enable the IDP configuration
        3.  
          Enroll the NetBackup primary server with the IDP
        4.  
          Manage an IDP configuration
        5.  
          Video: Configure single sign-on in NetBackup
      5. Troubleshooting SSO
        1.  
          Redirection issues
        2.  
          Unable to sign in due to authorization-related issues
    11. Managing role-based access control (RBAC)
      1.  
        RBAC features
      2.  
        Authorized users
      3. Configuring RBAC
        1.  
          Notes for using NetBackup RBAC
        2.  
          Add AD or LDAP domains
        3.  
          View users in RBAC
        4.  
          Add a user to a role (non-SAML)
        5.  
          Add a smart card user to a role (non-SAML, without AD/LDAP)
        6.  
          Add a user to a role (SAML)
        7.  
          Remove a user from a role
      4.  
        Default RBAC roles
      5. Add a custom RBAC role
        1.  
          Edit or remove a role a custom role
        2.  
          Add a custom RBAC role to restore Azure-managed instances
        3.  
          Add a custom RBAC role for a PaaS administrator
        4.  
          Add a custom RBAC role for a Malware administrator
      6.  
        Role permissions
      7.  
        Manage access permission
      8.  
        View access definitions
    12. Disabling access to NetBackup interfaces for OS Administrators
      1.  
        Disable command-line (CLI) access for operating system (OS) administrators
      2.  
        Disable web UI access for operating system (OS) administrators
  7. Section VII. Detection and reporting
    1. Detecting anomalies
      1. About backup anomaly detection
        1.  
          How a backup anomaly is detected
      2.  
        Configure backup anomaly detection settings
      3.  
        View backup anomalies
      4.  
        Disable backup anomaly detection and computation of entropy and file attributes for a client
      5.  
        About system anomaly detection
      6.  
        Configure system anomaly detection settings
      7.  
        Configure rules-based anomaly detection
      8.  
        Configure risk engine-based anomaly detection
      9.  
        View system anomalies
    2. Malware scanning
      1. About malware scanning
        1. Workflow for malware scanning
          1.  
            Malware scanning workflow for MSDP backup images using Agentless host as the scan host
          2.  
            Malware scanning workflow for the MSDP backup images that use the NetBackup client as the scan host
          3.  
            Malware scanning workflow for OST and AdvancedDisk
      2. Configuring a scan host pool
        1.  
          Prerequisites for scan host pool
        2.  
          Configure a new scan host pool
        3.  
          Add a new host in a scan host pool
      3. Managing a scan host
        1.  
          Add an existing scan host
        2.  
          Validating the scan host pool configuration
        3.  
          Remove the scan host
        4.  
          Activate or deactivate the scan host
        5.  
          Managing credentials for malware scanning
      4.  
        Configure resource limits for malware detection
      5. Perform a malware scan
        1.  
          Scanning backup images
        2.  
          Assets by policy type
        3.  
          Assets by workload type
      6. Managing scan tasks
        1.  
          View the malware scan status
        2.  
          Actions for malware scanned images
        3.  
          Recover from malware-affected images (clients protected by policies)
        4.  
          Recover from malware-affected images (clients protected by protection plan)
        5.  
          Clean file recovery for virtual workload (VMware)
    3. Usage reporting and capacity licensing
      1.  
        Track protected data size on your primary servers
      2.  
        Add a local primary server
      3.  
        View license types in usage reporting
      4.  
        Download usage reports
      5.  
        Scheduling reports for capacity licensing
      6.  
        Other configuration for incremental reporting
      7.  
        Troubleshooting failures for usage reporting and incremental reporting
    4. Reports
      1.  
        About the reports utility
      2.  
        Run a report
      3.  
        Copy a report text to another document
  8. Section VIII. NetBackup workloads and NetBackup Flex Scale
    1. NetBackup SaaS Protection
      1.  
        Overview of NetBackup for SaaS
      2.  
        Adding NetBackup SaaS Protection Hubs
      3.  
        Configuring the autodiscovery frequency
      4.  
        Viewing asset details
      5.  
        Configuring permissions
      6.  
        Troubleshooting SaaS workload issues
    2. NetBackup Flex Scale
      1. Managing NetBackup Flex Scale
        1.  
          Access NetBackup from the Flex Scale infrastructure management console
        2.  
          Manage NetBackup and the NetBackup Flex Scale cluster management from the NetBackup Flex Scale web UI
        3.  
          Access NetBackup Flex Scale from the NetBackup web UI
    3. NetBackup workloads
      1.  
        Protection of other asset types and clients
  9. Section IX. Administering NetBackup
    1. Management topics
      1.  
        Configuring the NetBackup Client Service
      2.  
        Units of measure used with NetBackup
      3.  
        NetBackup naming conventions
      4.  
        Wildcard use in NetBackup
    2. Managing client backups and restores
      1.  
        About server-directed restores
      2. About client-redirected restores
        1.  
          About restore restrictions
        2.  
          Allowing all clients to perform redirected restores
        3.  
          Allowing a single client to perform redirected restores
        4.  
          Allowing redirected restores of a specific client's files
        5.  
          Examples of redirected restores
      3.  
        About restoring the files that have Access Control Lists (ACLs)
      4.  
        About setting the original atime for files during restores on UNIX
      5.  
        Restoring the System State
      6.  
        About the backup and restore of compressed files on VxFS file systems
      7.  
        About backups and restores on ReFS
  10. Section X. Disaster recovery and troubleshooting
    1. Disaster recovery of NetBackup
      1.  
        About disaster recovery of NetBackup
    2. Managing Resiliency Platforms
      1.  
        About Resiliency Platform in NetBackup
      2.  
        Understanding the terms
      3. Configuring a Resiliency Platform
        1.  
          Add a Resiliency Platform
        2.  
          Configure a third-party CA certificate
        3.  
          Edit or delete a Resiliency Platform
        4.  
          View the automated or not-automated VMs
      4.  
        Troubleshooting NetBackup and Resiliency Platform issues
    3. Managing Bare Metal Restore (BMR)
      1.  
        About Bare Metal Restore (BMR)
      2.  
        Add a custom role for a Bare Metal Restore (BMR) administrator
    4. Troubleshooting the NetBackup Web UI
      1.  
        Tips for accessing the NetBackup web UI
      2.  
        If a user doesn't have the correct permissions or access in the NetBackup web UI
      3.  
        Unable to validate the user or group when configuring LDAP server
  11. Section XI. Other topics
    1. Additional NetBackup catalog information
      1. Parts of the NetBackup catalog
        1. NetBackup databases and configuration files
          1.  
            About the Enterprise Media Manager (EMM)
        2. About the NetBackup image database
          1.  
            About NetBackup image .f files
        3.  
          About the catalog backup of cloud configuration files
      2. Archiving the catalog and restoring from the catalog archive
        1.  
          Enabling intelligent catalog archiving (ICA) to reduce the number of .f files
        2.  
          Creating a catalog archiving policy
        3.  
          Catalog archiving commands
        4.  
          Catalog archiving considerations
        5.  
          Extracting images from the catalog archives
      3. Estimating catalog space requirements
        1.  
          NetBackup file size considerations on UNIX systems
        2.  
          Moving the image catalog
        3. About image catalog compression
          1.  
            Uncompressing the NetBackup catalog
      4. About the file hash search in NetBackup
        1.  
          Configuring the file hash server
        2.  
          Enabling the file hash server on the NetBackup primary server
        3.  
          Calculating the file hash
        4.  
          Searching the files using the file hash
        5.  
          Identifying the backups that have the file hash enabled
        6.  
          Removing the file hash from the backup
        7.  
          Migrating the file hash data from one server to another
        8.  
          Configuring the backup of file hash data on the file hash server
        9.  
          Restoring the file hash data to the file hash server
    2. About the NetBackup database
      1. About the NetBackup database installation
        1. About NetBackup primary server installed directories and files
          1.  
            About the bin directory
          2.  
            About the contents of the NetBackupDB and db directories
          3.  
            About the data directory
          4.  
            vxdbms.conf
        2.  
          NetBackup configuration entry
        3.  
          NetBackup database server management
        4.  
          The NetBackup database and clustered environments
      2. Post-installation tasks
        1.  
          Changing the NetBackup database password
        2.  
          Moving a database after installation
        3.  
          Copying the NetBackup databases
        4. Creating the NBDB database manually
          1.  
            Additional create_nbdb options
      3. Using the NetBackup Database Administration utility on Windows
        1. General tab of the NetBackup Database Administration utility
          1.  
            About fragmentation
        2. Tools tab of the NetBackup Database Administration utility
          1.  
            Changing the DBA password using the NetBackup Database Administration utility
          2.  
            Moving a NetBackup database
          3.  
            Exporting database schema and data
          4.  
            Copying or backing up a database
          5.  
            Restoring a database from a backup
      4. Using the NetBackup Database Administration utility on UNIX
        1.  
          Select/Restart Database and Change Password menu options
        2.  
          Database Space Management menu options
        3.  
          Database Validation Check and Rebuild menu options
        4.  
          Move Database menu options
        5.  
          Unload Database menu options
        6.  
          Backup and Restore Database menu options

About NetBackup auditing

Auditing is enabled by default in new installations. NetBackup auditing can be configured directly on a NetBackup primary server.

Auditing of NetBackup operations provides the following benefits:

  • Customers can gain insight from audit trails while they investigate unexpected changes in a NetBackup environment.

  • Regulatory compliance.

    The record complies with guidelines such as those required by the Sarbanes-Oxley Act (SOX).

  • A method for customers to adhere to internal change management policies.

  • Help for NetBackup Support in troubleshooting problems for customers.

About the NetBackup Audit Manager

The NetBackup Audit Manager (nbaudit) runs on the primary server and audit records are maintained in the Enterprise Media Manager (EMM) database.

An administrator can search specifically for:

  • When an action occurred

  • Failed actions in certain situations

  • The actions that a specific user performed

  • The actions that were performed in a specific content area

  • Changes to the audit configuration

Note the following:

  • The audit record truncates any entries greater than 4096 characters. (For example, policy name.)

  • The audit record truncates any restore image IDs greater than 1024 characters.

Actions that NetBackup audits

NetBackup records the following user-initiated actions.

Activity monitor actions

Canceling, suspending, resuming, restarting, or deleting any type of job creates an audit record.

Alerts and email notifications

If an alert cannot be generated or an email notification cannot be sent for NetBackup configuration settings. For example, SMTP server configuration and the list of excluded status codes for alerts.

Anomalies

When a user reports an anomaly as false positive, the action is audited and logged for that user.

Malware detection

When malware scan is triggered, malware scan status and malware scan configuration actions are audited.

Asset actions

Deleting an asset, such as a vCenter server, as part of the asset cleanup process is audited and logged.

Creating, modifying, or deleting an asset group as well any action on an asset group for which a user is not authorized is audited and logged.

Authorization failure

Authorization failure is audited when you use the NetBackup web UI, or the NetBackup APIs.

Catalog information

This information includes:

  • Verifying and expiring images.

  • Read the requests that are sent for the front-end usage data.

Certificate management

Creating, revoking, renewing, and deploying of NetBackup certificates and specific NetBackup certificate failures.

Certificate Verification Failures (CVFs)

Any failed connection attempts that involve SSL handshake errors, revoked certificates, or host name validation failures.

For certificate verification failures (CVFs) that involve SSL handshakes and revoked certificates, the timestamp indicates when the audit record is posted to the primary server. (Rather than when an individual certificate verification fails.) A CVF audit record represents a group of CVF events over a time period. The record details provide the start and the end times of the time period as well as the total number of CVFs that occurred in that period.

Disk pools and Volume pools actions

Adding, deleting, or updating disk or volume pools.

Hold operations

Creating, modifying, and deleting hold operations.

Host database

NetBackup operations that are related to the host database.

IRE configuration and states

Adding, updating, and deleting IRE allowed subnets or schedule. IRE external network is opened or closed by IRE schedule or by an administrator.

Logon attempts

Any successful or any failed logon attempts for the NetBackup web UI or the NetBackup APIs.

Policies actions

Adding, deleting, or updating policy attributes, clients, schedules, and backup selections lists.

Restore and browse image user actions

All the restore and browse image content (bplist) operations that a user performs are audited with the user identity.

To set an interval to periodically add audit records of the browse image (bplist) operations from the cache into the NetBackup database, use the DATAACCESS_AUDIT_INTERVAL_HOURS configuration option. Setting this configuration option prevents the NetBackup database size from increasing exponentially because of the bplist audit records.

See the NetBackup Administrator's Guide Volume I.

To add all the bplist audit records from the cache into the NetBackup database, run the following command on the primary server:

nbcertcmd -postAudit -dataAccess

Security configuration

Information that is related to changes that are made to the security configuration settings.

Starting a restore job

NetBackup does not audit when other types of jobs begin. For example, NetBackup does not audit when a backup job begins.

Starting and stopping the NetBackup Audit Manager (nbaudit).

Starting and stopping of the nbaudit manager is always audited, even if auditing is disabled.

Storage lifecycle policy actions

Attempts to create, modify, or delete a storage lifecycle policy (SLP) are audited and logged. However, activating and suspending an SLP using the command nbstlutil are not audited. These operations are audited only when they are initiated from a NetBackup graphical user interface or API.

Storage servers actions

Adding, deleting, or updating storage servers.

Storage units actions

Adding, deleting, or updating storage units.

Note:

Actions that are related to storage lifecycle policies are not audited.

Token management

Creating, deleting, and cleanup of tokens and specific token issuing failures.

User action that fails to create an audit record

If auditing is enabled but a user action fails to create an audit record, the audit failure is captured in the nbaudit log. NetBackup status code 108 is returned (Action succeeded but auditing failed). The NetBackup does not return an exit status code 108 when auditing fails.

Actions that NetBackup does not audit

The following actions are not audited and do not display in the audit report:

Any failed actions.

NetBackup logs failed actions in NetBackup error logs. Failed actions do not display in audit reports because a failed attempt does not bring about a change in the NetBackup system state.

The effect of a configuration change

The results of a change to the NetBackup configuration are not audited. For example, the creation of a policy is audited, but the jobs that result from its creation are not.

The completion status of a manually initiated restore job

While the act of initiating a restore job is audited, the completion status of the job is not audited. Nor is the completion status of any other job type, whether initiated manually or not. The completion status is displayed in the Activity Monitor.

Internally initiated actions

NetBackup-initiated internal actions are not audited. For example, the scheduled deletion of expired images, scheduled backups, or periodic image database cleanup is not audited.

Rollback operations

Some operations are carried out as multiple steps. For example, creating an MSDP-based storage server consists of multiple steps. Every successful step is audited. Failure in any of the steps results in a rollback, or rather, the successful steps may need to be undone. The audit record does not contain details about rollback operations.

Host properties actions

Changes made with the bpsetconfig or the nbsetconfig commands, or the equivalent property in host properties, are not audited. Changes that are made directly to the bp.conf file or to the registry are not audited.