Kaspersky Anti Targeted Attack Platform

Creating a backup copy and restoring the program from backup

If you are using the non fault-tolerant version of Kaspersky Anti Targeted Attack Platform, you can create a backup copy of the program and then restore it from the backup copy.

For a standalone Central Node server, you can create a backup copy of the data from this Central Node server.

If you are using the

and , you can:

  • Create a backup copy of PCN data.
  • Create a backup copy of SCN data.

    Restoring data from a backup copy of the SCN will change the role of the server from SCN to standalone Central Node server.

Follow the procedure for creating the backup copy of the program on the server for which you want to create a backup copy of the data.

Kaspersky Anti Targeted Attack Platform may contain user data and other confidential information. The Kaspersky Anti Targeted Attack Platform administrator must independently ensure the security of this data when creating a backup copy of the program, when replacing equipment on which the program is installed, or in other cases when it may be necessary to permanently delete data. The Kaspersky Anti Targeted Attack Platform administrator bears responsibility for access to data stored on program servers.

You can create a backup copy of the following data:

  • The program database.
  • Objects in Storage.
  • Files from alerts generated during a rescan.
  • Sandbox artifacts.
  • Configuration files.
  • Information about KATA and KEDR licenses.
  • Central Node or PCN settings:
    • If you are using a standalone Central Node server, a backup copy of Central Node settings is created.
    • If you are using the distributed solution and multitenancy mode and are managing the PCN server, a backup copy of PCN settings is created.
    • If you are using the distributed solution and multitenancy mode and are managing the SCN server, you can create a backup copy of the SCN, but restoring data from a backup copy will change the role of the server from SCN to standalone Central Node server.

You can clear the directory before creating a backup copy of the program.

Before the program is restored from a backup copy, the following is cleared on the Central Node or PCN server on which the program is being restored:

  • The program database.
  • Objects in Storage.
  • Files from alerts generated during a rescan.
  • Sandbox artifacts.
  • Configuration files.
  • Information about KATA and KEDR licenses.
  • Central Node or PCN settings.

    Contents and volume of data exported for the creation of a backup copy of the program

    Maximum data volume

    Data type

    Exported data

    Program operation mode

    4 GB

    • Central Node settings.
    • The program database on Central Node:
    • Alerts and VIP statuses of alerts
    • Tasks and task execution results
    • Policies
    • User-defined TAA (IOA) rules and exclusions
    • User-defined IDS rules and exclusions
    • IOC files
    • Scan exclusion rules
    • Information about files in Storage
    • Information about quarantined objects
    • List of computers with Endpoint Agent
    • Reports and report templates
    • User account data
    • Notifications

    Central Node settings, if selected.

    Program databases, by default.

    Standalone Central Node server.

    4 GB

    PCN settings.

    Custom

    Distributed solution and multitenancy mode.

     

    4 GB

    SCN settings.

    Custom

    As for a standalone Central Node server.

    Distributed solution and multitenancy mode.

    4 GB

    Program databases on the PCN:

    • Alerts and VIP statuses of alerts
    • Task execution results
    • Policies
    • User-defined TAA (IOA) rules and exclusions
    • User-defined IDS rules and exclusions
    • IOC files
    • List of data excluded from the scan
    • Information about files in Storage
    • Information about quarantined objects
    • List of Kaspersky Endpoint Agent hosts
    • Reports and report templates
    • User account data
    • Notifications

    Default

    Distributed solution and multitenancy mode.

    No

    Configuration files.

    Yes

    All modes.

    No

    KATA and KEDR licenses.

    Yes

    All modes.

    300 GB

    Backup

    Custom

    All modes.

    300 GB

    Sandbox artifacts.

    Custom

    All modes.

    300 GB

    Files from alerts generated during a rescan.

    Custom

    All modes.

    No

    Events database.

    None.

    All modes.

Files that are in the scan queue when the backup copy of the program is created are not exported.

The versions of the program being restored must match the version of the program installed on the server. If the versions of the programs do not match, an error message is displayed when the program restoration is initiated, and the restoration process is terminated.

In this Help section

Creating a backup copy of Central Node server settings from the program administrator menu

Downloading a file containing a backup copy of server settings from the Central Node or PCN server to the hard drive of the computer

Uploading a file containing a backup copy of server settings from your computer to the Central Node server

Restoring server settings from a backup copy using the program administrator menu

Creating a backup copy of the program in Technical Support Mode

Restoring the program from a backup copy in Technical Support Mode

Page top
[Topic 198854]

Creating a backup copy of Central Node server settings from the program administrator menu

To create a backup copy of the Central Node (PCN or SCN in distributed solution and multitenancy mode), do the following in the administrator menu of the server:

  1. In the list of sections of the program administrator menu, select the System administration section.
  2. Press ENTER.

    This opens the action selection window.

  3. In the list of actions, select Backup/Restore settings.
  4. Press ENTER.

    This opens the Backup/Restore settings window.

  5. In the list of actions, select New.
  6. Press ENTER.

    This opens the Backup settings window.

  7. Click Back up.

A backup copy of server settings is created.

Page top
[Topic 162400]

Downloading a file containing a backup copy of server settings from the Central Node or PCN server to the hard drive of the computer

It is recommended to save files containing a backup copy of the Central Node server settings to the hard drive of your computer.

To download a file containing a backup copy of the Central Node server settings to the hard drive of your computer, run the following command in the command line interface of the Linux operating system on your computer:

scp <name of the account used for working in the administrator menu and in the server management console>@<IP address of the server>:<name of the file containing the backup copy of the program in the form of settings-<date and time of backup copy creation>.tar.gz>

Example:

Command for downloading to the hard drive of your computer an archive containing a backup copy of server settings that was created on a Central Node server with the IP address 10.0.0.10 under the "admin" account on April 10, 2020 at 10 hours 00 minutes 00 seconds:

scp admin@10.0.0.10:settings-20200410-100000.tar.gz

The file containing a backup copy of server settings is saved to the hard drive of your computer in the current directory.

Page top

[Topic 182331]

Uploading a file containing a backup copy of server settings from your computer to the Central Node server

To upload a file containing a backup copy of server settings from the hard drive of your computer to the Central Node server, run the following command in Technical Support Mode:

scp <name of the file containing a backup copy of server settings in the form of settings-<backup copy creation date and time>.tar.gz> <name of the account used for working in the administrator menu and in the server management console>@<IP address of the server>:

Example:

Command for uploading an archive containing a backup copy of server settings created on April 10, 2020 at 10 hours 00 minutes 00 seconds to the Central Node server with the IP address 10.0.0.10 under the "admin" account:

scp settings-20200410-100000.tar.gz admin@10.0.0.10:

The file containing the backup copy of server settings is uploaded to the Central Node server in the current directory.

Page top

[Topic 182332]

Restoring server settings from a backup copy using the program administrator menu

To restore Central Node server settings from a backup copy, you must first create a backup copy of current server settings. In case of an error when restoring server settings you will be able to use a backup copy of server settings.

To restore server settings from a previously created backup copy, perform the following actions in the administrator menu of the server:

  1. In the list of sections of the program administrator menu, select the System administration section.
  2. Press ENTER.

    This opens the action selection window.

  3. In the list of actions, select Backup/Restore settings.
  4. Press ENTER.

    This opens the Backup/Restore settings window.

  5. In the list of files containing backup copies of the program, select the file from which you want to restore the server settings.

    If the necessary file is not listed, upload the file containing the backup copy of the settings to the server.

  6. Press ENTER.

    This opens the action selection window.

  7. In the list of actions, select Restore <name of the file with the backup copy of server settings>.
  8. Press ENTER.

    This opens the action confirmation window.

  9. Click Restore.

Server settings are restored from the selected file.

If the hardware configuration of the Central Node server on which the backup copy was created differs from the hardware configuration of the server on which you are planning to restore the server settings, you need to reconfigure the application scaling settings after restoring.

Page top
[Topic 177456]

Creating a backup copy of the program in Technical Support Mode

To create a backup copy of Kaspersky Anti Targeted Attack Platform, run the following command in Technical Support Mode of the server:

kata-backup-restore backup

You can also specify one or multiple parameters for this command (see the table below).

You can use the -h command to receive tips on using parameters.

Parameters of the command for creating a backup copy of Kaspersky Anti Targeted Attack Platform

Required parameter

Parameter

Description

Yes

-b <path>

Create a file containing a backup copy of the program at the specified path,

where <path> is the absolute path or relative path to the directory in which the file with the backup copy of the program is created.

No

-c

Clear the directory before saving the program backup file.

No

-d <number of stored files>

Specify the maximum number of files from the backup copy of the program stored in the directory, where <number> is the number of files.

No

-e

Save files in Storage.

No

-q

Save files in quarantine.

No

-a

Save files awaiting rescan.

No

-s

Save Sandbox artifacts.

No

-n

Save Central Node or PCN settings.

No

-l <filepath>

Save the command execution result to a file, where <filepath> is the name of the event log file, including the absolute path or relative path to the file.

If additional settings are not defined, the backup copy of Kaspersky Anti Targeted Attack Platform contains only databases (alerts database, VIP status details, the list of data excluded from the scan, notifications).

All files containing a backup copy of the program are saved to one TAR archive. Archive file name: data_kata_ddmmyyyyhhMM, where ddmmyyyy is the date and hhMM is the hour and minute when the backup copy of the program was created. The name of the database is KATA5.0.sql for the backup copy of the program version 5.0.

Example:

Command for creating a backup copy of the program:

kata-backup-restore backup -b <path> -c -d <number of stored files> -e -q -a -s -n -l <filepath>

Page top

[Topic 177426]

Restoring the program from a backup copy in Technical Support Mode

To restore Kaspersky Anti Targeted Attack Platform from a backup copy, you must first create a backup copy of the current state of the program and download it to the hard drive of your computer. If an error occurs when restoring the program or if it becomes necessary to reinstall Kaspersky Anti Targeted Attack Platform, you will be able to use the saved copy of the program.

The versions of the program being restored must match the version of the program installed on the server. If the versions of the programs do not match, an error message is displayed when the program restoration is initiated, and the restoration process is terminated.

To restore Kaspersky Anti Targeted Attack Platform from a backup copy, run the following command in Technical Support Mode of the server:

kata-backup-restore restore

You can also specify one or multiple parameters for this command (see the table below).

You can use the -h command to receive tips on using parameters.

Parameters of the command for restoring Kaspersky Anti Targeted Attack Platform from a backup copy

Required parameter

Parameter

Command description

Yes

-r <path>

Restore data from a file containing a backup copy of the program,

where <path> is the full path to the file containing a backup copy of the program.

No

-l <filepath>

Save the command execution result to a file, where <filepath> is the name of the event log file, including the absolute path or relative path to the file.

Example:

Command for restoring the program from a backup copy:

kata-backup-restore restore -r <path> -l <filepath>

Page top

[Topic 176863]