What you should know about backup

Management responsibilities

The System administrator must protect logged data and set frequency for the various types of backups.

Backup methods

RCS saves all data in databases in the specified folder when editing RCS settings. See "Editing Master Node settings"

A backup can save one or more types of data. Backup types are:

Metadata type backup

The metadata backup type is fast and saves the entire system configuration, allowing normal system operations to be quickly restored in the event of problems. This type of backup does not include collected evidence. Daily backup is recommended.

WARNING: agents installed on various devices may be lost without a recent metadata backup.

NOTE: the job that runs weekly metadata backup is set by default and enabled whenever the system is rebooted. The default job cannot be deleted.

Full type backup

Full backup contains all evidence, therefore this could take a long time. Since it can be restored after a metadata backup, it is recommended once a month.

Operation type backup

The operation backup saves all open and closed operations. Since it can be restored after a metadata backup, it is recommended once a month.

Target type backup

The target backup saves all opened and closed target data. Since it can be restored after a metadata backup, it is recommended once a month.

Incremental backup

Full, operation and target backups can also be incremental. This way the system saves data generated from the date-time of the last backup. The first incremental backup is always complete (full, operation or target). Only subsequent backups are incremental.

NOTE: if the incremental option is removed and reapplied to a job, the next backup of that job will be complete.

Tip: name the job so it is later recognized as an incremental backup (i.e.: "Increm_lastWeek").

We suggest you run a complete backup (full, operation or target) once a month and an incremental backup once a week.

Backup restore for severe reasons

CAUTION: restoring a backup should only be considered in severe situations such as replacing a database.

A backup must be restored whenever a server is replaced.

Backup data restore

IMPORTANT: backup restore is never destructive. For this reason, restore should not be used to restore accidentally changed elements.

Some examples are provided below:

If after the last backup Then restore
an element was deleted

restores the deleted element.

an element was edited

leaves the element changed.

a new element was added

leaves the element changed.

IMPORTANT: backup does not restore information on operations that were erroneously closed (deleted).

IMPORTANT: to restore an incremental backup, restore them all starting with the oldest.