Security Compliance

Configure Backups on your SEM Appliance

This article describes how to configure the SEM appliance to run scheduled backups according to your requirements and preferences. Use these backups for data retention and disaster recovery.

First published date

2/4/2019 4:03 PM

Last published date

6/4/2025 3:56 PM

Overview

You can configure your Security Event Manager (formerly Log & Event Manager) appliance to run scheduled backups to a remotely accessible NFS share according to your requirements and preferences.

If your SEM appliance is hosted on Azure or AWS and if you have the option to backup the entire VM via Azure or AWS backup services, then you should choose that option. Alternatively, you can use the above Network share method.

Product section

Security Event Manager

Resolution

Backup types 

This section describes the three primary SEM backup options. The procedure for scheduling these backups is the same. 

Note: You cannot merge backup data with live data at this time. Use these backups for data retention and disaster recovery only.

archiveconfig

Schedule or run this backup to back up the normalized alert (default) database of your SEM appliance. Since it backs up everything on the database, this backup file grows as your database grows. The entire contents of the database on the SEM will be backed up the first time this is configured and run. Each subsequent backup performs an incremental backup to the network share. If you have a separate SEM appliance dedicated to this database, schedule or run this backup on the dedicated database appliance.

Note: If the database backup on the network share is moved or deleted, the entire contents of the SEM database will be backed up at the next interval. You can manually move or archive the oldest partitions on the network share.
Recommended schedule: Daily
File Name: SolarWindsLEMAlertDBArchive


backupconfig

Schedule or run this backup to back up all configuration settings on your SEM appliance. These settings include all user-defined groups, rules, scheduled nDepth searches, and users. This backup does not back up any database log data. During initial SEM deployment, we recommend daily or weekly backups, but backups can be less frequent after SEM is fully deployed and changes are infrequent.

Recommended schedule: Weekly
File Name: TriGeoBackup


logbackupconfig 

Schedule or run this backup to back up the original syslog data on your SEM appliance. The syslog data is a temporary holding place for data, containing data from a few hours up to 100 days maximum, depending upon how the log rotation is set. This backup is optional since archiveconfig backs up the corresponding alert database.

Recommended schedule: Weekly or Monthly, if used
File Name: TriGeoLogBackup

 

Schedule or run backups on your SEM appliance

The procedures are the same for scheduling and running each of the SEM appliance backups. Below are the options you can select for your backup. 

 # OPTION DESCRIPTION
 1 daily Perform daily full backup at 6:25AM
 2 weekly Perform weekly full backup Sunday at 6:47AM
 3 monthly Perform monthly full backup the first of the month at 6:52AM
 4 never Unschedule any configured backup
 5 once Run a one-time backup
 6 exit Exit configuration

 

  1. Connect to your SEM virtual appliance using either the vSphere "console" view, or an SSH client such as PuTTY.
  2. If you are using an SSH client, log in to your SEM virtual appliance using your CMC credentials.
  3. At the cmc> prompt, enter manager.
  4. At the cmc::cmm prompt, enter the name of the backup you want to schedule or run. You can select  archiveconfigbackupconfig, or logbackupconfig.
  5. To start the backup script, press Enter.
  6. Review the current backup settings, and then enter the number that corresponds to the option you want to choose.
  7. To confirm your selection, enter y.
  8. Enter and confirm the file location, user account, and password information you want your SEM appliance to use for the scheduled backups.
    • Enter the file location in UNC format (for example, \\server\share). If your SEM appliance cannot resolve host names, use the server's IP address instead.
    • SolarWinds recommends that you provide a service account for the SEM appliance to use to run backups. Otherwise, you will have to update your backup settings every time the user's password changes.
    • The user you provide in this procedure must have write permissions to the share used for the backups.
  9. If you want to run the backup immediately, enter y when prompted. SolarWinds recommends that you only run the initial backup of archiveconfig and logbackupconfig during off-peak hours, as they can be very resource intensive. After an initial backup is completed, it performs incremental backups which take significantly less resources.

Each time the backups run, your SEM manager displays an alert similar to the following in the default SolarWinds Alerts filter:
Alert Name: InternalInfo
EventInfo: ManagerMonitor Info: Backup Done with backup. InsertionIP: gman Manager: gman DetectionIP: 10.10.10.10 InsertionTime: 10:11:26 Mon Jan 30 2012 DetectionTime: 10:11:25 Mon Jan 30 2012 Severity: 2 ToolAlias: Manager Monitor InferenceRule: ProviderSID: ManagerMonitor Manager Backup Info ExtraneousInfo: DUMP: Date of this level 0 dump: Mon Jan 30 09:30:32 201