Security Compliance

Restore SEM configurations

This article describes how to restore a SEM configuration when part of the configuration (such as a rule, group, connector profile, or email template) was accidentally deleted or you are performing disaster recovery testing.

First published date

10/17/2018 2:58 PM

Last published date

4/29/2021 12:46 PM

Overview

This article describes how to restore a Security Event Manager (formerly Log & Event Manager) configuration when part of the configuration (such as a rule, group, connector profile, or email template) was accidentally deleted or you are performing disaster recovery testing.

Product section

Security Event Manager

Resolution

Restore the SEM configuration  

To perform the following steps, you will need a backup configuration installed on a shared network.

  1. Open a VMware vSphere or Microsoft Hyper-V console in SEM or establish an SSH connection or PuTTY using cmc as the login.
  2. Enter appliance to access the Appliance menu.
  3. Run the import command to start importing the configuration.
    Note: Verify the date on the backup to avoid losing any previous configurations.
  4. Follow the prompts until you are pointed to the network location where the configuration is stored. For example, a file named TriGeoBackup or TriGeoBackupYYYYMMDD is the ShareName.
    Note: The ShareName is case sensitive.

When completed, the Manager service is started which allows SEM to receive the data. We recommend rebooting SEM to make sure that there is a clean startup.

Note: Perform the reboot under the Appliance menu using the reboot command.


Set up the SEM configuration backup 

  1. Open a vSphere or Hyper-V console in SEM or establish an SSH connection or PuTTY using cmc as the login.
  2. Enter Manager to access the Manager menu.
  3. Enter backupconfig to configure the backup.
    Note: The ShareName is case sensitive.
  4. Follow the prompts to proceed with the configuration:
    1. Select Daily (1), Weekly (2), or Monthly (3) for the frequency of the backups or select N to use a non-existent backup.
    2. Enter \\<server-IP-hostname>\<share-name>.
      Note: The ShareName is case sensitive.
    3. Enter your credentials or service account credentials to access the shared network.
    4. Select Y to append the date.
    5. Select Y to run the backup now.
  5. Make sure that the shared network has a single file named TriGeoBackup or TriGeoBackupYYYYMMDD, and is about 1 GB in size.

See Configure Backups on your SEM Appliance for details about backing up your database (archiveconfig) each day.