Welcome to your hub for enterprise data protection discussions. Learn more about recent changes to the VOX Community here.
Forum Widgets
Recent Discussions
Script for listing Policy name and vm host name?
Greetings, Has anyone found a way to get the vm hostname/display name from a VMWare Intelligent Policy that uses a vmquery to find the vm host to backup? I'd like to script this so I can feed it a list of about 500 servers / vm's and verify that they are in an active backup policy and the backups are running. Anybody done this already on Linux via bash script and NetBackup commands?DPeaco33 minutes agoModerator5Views0likes1CommentTake Full Advantage of NetBackup and Syslog Forwarding - SIEM and SOAR
According to a survey conducted by Splunk, as many as 67% of organizations are investing in both SIEM (Security information and event management) and as much as 88% are investing in SOAR (Security Orchestration Automation & Response) platforms, sometimes also including XDR (eXternal Detection and Response) platforms, many of which are cloud-based. NetBackup can integrate with these tools in a simple universal method. NetBackup audit messages include sever new audit categories and are consistently formatted to be consumed by 3 rd party tools using APIs, CLIs or being captured from operating system messages logs. This audit capturing mechanism aligns with the Executive Orders (EOs) guidance on Event Logging (EL), enabling a reliable method of compliance. Ensure that you have selected to export the audit messages to the system logs. This is easily enabled under the Security > Security Events area of the NetBackup WebUI (see figure 1). By default, this feature is not enabled, and once enabled, there are no default messages until the next audit event. Figure 1: Enabling audit events exported to the system log of the primary server NetBackup can always manually export the audit events using the nbauditreport command on the Primary server, but leveraging the export allows for automation. NetBackup audit messages are categorized (see Figure 2). The audit messages that are exported can further be customized by category, opening up a wide array of possibilities for integrations with both SIEM and SOAR platforms with different triggers for each category, as well as removing categories that you do not wish to export. The primary consumer of this data would normally be a SIEM platform, in order to perform analytics, generate alerts and often provide further analysis in the form of reports. SOAR actions can follow triggers from the SIEM platform, or trigger directly from certain event patterns, in some cases, according to your level of customization in the SIEM and SOAR platforms. Below is the complete list of NetBackup audit event categories, with their readable name next to the category tag in parentheses. Several new categories have been added to NetBackup auditing. Alert (ALERT) Config (CONFIG) Malware impacted (MALWARE_IMPACTED) Anomaly (ANOMALY) Connection (CONNECTION) Malware Scan Status (MALWARE_SCAN_STATUS) Anomaly New (ANOMALY_NEW) Credential (CREDENTIALS) Malware Scan Trigger (MALWARE_SCAN_TRIGGER) Asset (ASSET) Credential Schema (CREDENTIAL_SCHEMA) Policy (POLICY) Audit configuration (AUDITCFG) Data access (DATAACCESS) Pool (POOL) Audit database (AUDITDB) Discovery (DISCOVERY) Protection Plan (PROTECTION_PLAN_SVC) Audit service (AUDITSVC) Event log (EVENT_LOG) Retention Level (RETENTION_LEVEL) Authorization failure (AZFAILURE) Hold (HOLD) Security configuration (SEC_CONFIG) Paused clients (PAUSED_CLIENTS) Host (HOST) Storage Lifecycle Policy (SLP) Bare Metal Restore (BMR) Intelligent group (ASSETGROUP) Storage server (STORAGESRV) Bp.conf (BPCONF) Job (JOB) Storage units (STU) Catalog (CATALOG) Licensing (LICENSING) Token (TOKEN) Certificate (CERT) Login (LOGIN) User (USER) Figure 2: A list of all audit categories available for export customization for NetBackup 10.1 Observe an example from the ANOMALY_NEW message in the Linux system log in Figure 3: {Month} ## HH:MM:SS {host name} nbaudit: DESCRIPTION: Anomaly detected on client ‘{client name}’ with job ID ‘#’, backup ID ‘{backupid}’ and severity ‘LOW’. | USER: nb-service-user@host | CATEGORY: ANOMALY_NEW | ACTION: CREATE | REASON: | DETAILS: 0 attribute(s) Figure 3: An example audit message in the Linux system log For Windows platforms, the messages will be in the Application Event Viewer in Figure 4: Figure 4: An example audit message in the Windows Event Viewer The category is aligned with one of the selectable areas to export to the system logs, allowing flexible deployment to focus on the most important areas. Different categories will have varying levels of information, especially in the Details section, but the formatting will be consistent with sections delimited by the “|” (pipe) character and always originate from the nbaudit (NetBackup Audit Manager) process. With these messages, SIEM platforms can collect, categorize, trigger and alert according to your organizations needs and business processes. Actions taken to change the protection status of a NetBackup client are also audited. Figure 5: Protection Status webUI Dashboard widget Within NetBackup, there is now Protection Status (see Figure 5) for a NetBackup client. When malware scan reports infected files, NetBackup offers an automated method to intercept and pause certain data protection activities for specific clients - these include future backups, duplications, or replications and expiration of backups. This helps prevent the spread of malware within the backup environment. A NetBackup client’s Protection Status can also be manually paused (see figure 6). Figure 6: Protection Status options in the NetBackup WebUI Summary SIEM, SOAR and XDR platforms are popular tools for combating unwanted trends and unsanctioned actions in IT ecosystems. NetBackup Audit messages can now be custom filtered and consumed by SIEM platforms by scanning the system log of the primary server, and digesting that information to provide reports, insights, and alerts. Automated response integration within NetBackup can automatically pause clients to stop any spread of undesired data, and SOAR integrations allow further customized actions based on triggers in the various categories of messages. NetBackup adds more capability to your ransomware response plans with insight and control with audit messaging.ChristopherW10 hours agoLevel 33.7KViews1like1CommentAnother duplication Question for Netbackup
Netbackup 10.5 Windows environment one primary server as master/media All Tapes are LTO6 (about 350 Archive Tapes with expiration set to Infinity most in the same volume pool but we do have tapes a few different volume pools). Currently Two Libraries - Scalar Quantum i500 robot type TLD (six fiber lto6 IBM tape drives in one library & four fiber Lto6 IBM drives in the other i500) SNIP of the LTO6 library Storage Units): We are obtaining quotes for a Quantum i6 robot type TLD containing LTO9 fibre IBM tape drives. (I know LtO9 drives cant READ or WRITE LTO6 tapes) This is my thinking and I need to know if Im on the right page sort of speak before we spend money on a tape generation that cant read or write our current tapes. Plan is to still continue to have the two i500 LTO6 libraries online when the new i6 LTO9 Library is bought and put online in the same netbackup primary master/media environment. Therefore we would have the two i500 LTO6 libraries and a brand new i6 LTO9 library As you see in the above snip the storage units are seen as a whole and not by drives (whether thats possible to see it by drives or not?). For example - currently daily backups/fulls are set to either use one library or the other library and also some policies have a storage unit group which it can use either library. I checked the compatibility doc/pdf and it appear a Quantum i6 with LTO9 IBM drives are compatible with Netbackup 10.5. Question Can I perform duplication via Netbackup Admin Console using the CATALOG | Action = Duplicate, and go from a LTO6 Archive tape (expiration date = infinity) that would be located in our LTO6 i500 quantum library and DUPLICATE the Image(s) to a LTO9 tape / drive in the new i6 quantum library we plan on buying containing LTO9 tape drives.? Once in the "Setup Duplication Variables" dialog box, the STORAGE UNIT (below SNIP) should be the library Im duplicating to or the destination - correct? - which would be the new LTO9 library. Is this doable /correct? Please advise SNIP: ALSO - For duplication does the new LTO9 tapes media type/density need to match the LTO6 or does that not matter? Im always a little confused here. Im thinking it should match. Thanks - BCbc14104 days agoLevel 632Views0likes1Commentstatus: 96: unable to allocate new media for backup
Hi, my backups are failing with the following error. Jun 11, 2025 5:01:02 PM - requesting resource LCM_HONETBKUPSRV-hcart3-robot-tld-0 Jun 11, 2025 5:01:02 PM - granted resource LCM_HONETBKUPSRV-hcart3-robot-tld-0 Jun 11, 2025 5:01:02 PM - started process RUNCMD (pid=1447098) Jun 11, 2025 5:01:02 PM - begin Duplicate Jun 11, 2025 5:01:03 PM - Info bpduplicate (pid=1447098) window close behavior: Suspend Jun 11, 2025 5:01:03 PM - Info bpduplicate (pid=1447098) The data-in-transit encryption (DTE) is enabled, as the DTE mode of the backup image is set to 'On' Jun 11, 2025 5:01:03 PM - Info bptm (pid=1447102) start Jun 11, 2025 5:01:03 PM - Info bptm (pid=1447102) Encrypting data-in-transit Jun 11, 2025 5:01:03 PM - started process bptm (pid=1447102) Jun 11, 2025 5:01:03 PM - Info bptm (pid=1447102) start backup Jun 11, 2025 5:01:03 PM - Info bpdm (pid=1447106) started Jun 11, 2025 5:01:03 PM - Info bpdm (pid=1447106) Encrypting data-in-transit Jun 11, 2025 5:01:03 PM - started process bpdm (pid=1447106) Jun 11, 2025 5:01:03 PM - Info bpdm (pid=1447106) reading backup image Jun 11, 2025 5:01:03 PM - Info bpdm (pid=1447106) using 30 data buffers Jun 11, 2025 5:01:03 PM - Info bpdm (pid=1447106) requesting nbjm for media Jun 11, 2025 5:01:03 PM - Info bptm (pid=1447102) Waiting for mount of media id K686L6 (copy 2) on server HONETBKUPSRV. Jun 11, 2025 5:01:03 PM - started process bptm (pid=1447102) Jun 11, 2025 5:01:03 PM - mounting K686L6 Jun 11, 2025 5:01:03 PM - Info bptm (pid=1447102) INF - Waiting for mount of media id K686L6 on server HONETBKUPSRV for writing. Jun 11, 2025 5:01:03 PM - requesting resource HONETBKUPSRV-hcart3-robot-tld-0 Jun 11, 2025 5:01:03 PM - requesting resource @aaaad Jun 11, 2025 5:01:03 PM - reserving resource @aaaad Jun 11, 2025 5:01:03 PM - resource @aaaad reserved Jun 11, 2025 5:01:03 PM - granted resource K686L6 Jun 11, 2025 5:01:03 PM - granted resource IBM.ULT3580-HH6.000 Jun 11, 2025 5:01:03 PM - granted resource HONETBKUPSRV-hcart3-robot-tld-0 Jun 11, 2025 5:01:03 PM - granted resource MediaID=@aaaad;DiskVolume=honetbkup;DiskPool=DataDomian;Path=honetbkup;StorageServer=172.16.11.5;MediaServer=HONETBKUPSRV Jun 11, 2025 5:01:03 PM - ended process 0 (pid=1447098) Jun 11, 2025 5:01:05 PM - begin reading Jun 11, 2025 5:01:52 PM - Info bptm (pid=1447102) media id K686L6 mounted on drive index 0, drivepath /dev/tape/by-path/pci-0000:01:00.0-fc-0x2002000e11167dfd-lun-0-nst, drivename IBM.ULT3580-HH6.000, copy 2 Jun 11, 2025 5:01:52 PM - Error bptm (pid=1447102) incorrect media found in drive index 0, expected K686L6, found TNK686, FREEZING K686L6 Jun 11, 2025 5:01:52 PM - current media K686L6 complete, requesting next media __ANY__ Jun 11, 2025 5:02:49 PM - Info bptm (pid=1447102) Waiting for mount of media id 1AOLL6 (copy 2) on server HONETBKUPSRV. Jun 11, 2025 5:02:49 PM - started process bptm (pid=1447102) Jun 11, 2025 5:02:49 PM - mounting 1AOLL6 Jun 11, 2025 5:02:49 PM - Info bptm (pid=1447102) INF - Waiting for mount of media id 1AOLL6 on server HONETBKUPSRV for writing. Jun 11, 2025 5:02:49 PM - granted resource 1AOLL6 Jun 11, 2025 5:02:49 PM - granted resource IBM.ULT3580-HH6.000 Jun 11, 2025 5:02:49 PM - granted resource HONETBKUPSRV-hcart3-robot-tld-0 Jun 11, 2025 5:03:41 PM - Info bptm (pid=1447102) media id 1AOLL6 mounted on drive index 0, drivepath /dev/tape/by-path/pci-0000:01:00.0-fc-0x2002000e11167dfd-lun-0-nst, drivename IBM.ULT3580-HH6.000, copy 2 Jun 11, 2025 5:03:41 PM - Error bptm (pid=1447102) incorrect media found in drive index 0, expected 1AOLL6, found 311AOL, FREEZING 1AOLL6 Jun 11, 2025 5:03:41 PM - current media 1AOLL6 complete, requesting next media __ANY__ Jun 11, 2025 5:04:36 PM - Error nbjm (pid=1442986) NetBackup status: 96, EMM status: No media is available Jun 11, 2025 5:04:36 PM - Info bptm (pid=1447102) EXITING with status 96 <---------- Jun 11, 2025 5:04:36 PM - Error nbjm (pid=1442980) NetBackup status: 96, EMM status: No media is available Jun 11, 2025 5:04:38 PM - Error bpdm (pid=1447106) media manager terminated by parent process Jun 11, 2025 5:04:43 PM - Error bpduplicate (pid=1447098) host HONETBKUPSRV backup id HOACSSRV19.IFL.NET_1749642400 read failed, media manager killed by signal (82). Jun 11, 2025 5:04:43 PM - Error bpduplicate (pid=1447098) host HONETBKUPSRV backupid HOACSSRV19.IFL.NET_1749642400 write failed, unable to allocate new media for backup, storage unit has none available (96). Jun 11, 2025 5:04:43 PM - Error bpduplicate (pid=1447098) Duplicate of backupid HOACSSRV19.IFL.NET_1749642400 failed, unable to allocate new media for backup, storage unit has none available (96). Jun 11, 2025 5:04:43 PM - Error bpduplicate (pid=1447098) Status = no images were successfully processed. Jun 11, 2025 5:04:43 PM - end Duplicate; elapsed time 0:03:41 Jun 11, 2025 5:04:43 PM - Error nbpem (pid=1443028) duplicate exited with status 191 (no images were successfully processed) no images were successfully processed(191) I have found an article related to this problem: https://www.veritas.com/support/en_US/article.100023592 According to this article I am changing the Max Mounts and Expiration Date of the Media ID but it is not changing.SaadHasnat4 days agoLevel 249Views0likes4Commentswhat is a catalog backup?
Hi What information is backed up when you back up the catalog? And can the catalog data backed up from the Windows master server be restored to the Linux master server (between different operating systems)? Finally, after backing up the catalog, general files and drpkg files are generated, and I am curious about the difference between the two files. Thanks.39Views0likes1CommentImage Cleanup - error 2027
Hello! At the moment, we periodically receive a massive error - (2027) The media server is not active. Image Cleanup performs correctly in the vast majority of tasks. Job Type - Image Cleanup ...... Apr 26, 2025 6:13:10 AM - Info nbdelete (pid=9992) deleting expired images. Media Server: media4003 Media: @aaaeE Apr 26, 2025 6:13:10 AM - Error nbdelete (pid=9992) Cannot obtain resources for this job : error [2027] Apr 26, 2025 6:13:10 AM - requesting resource @aaaeE Apr 26, 2025 6:13:10 AM - Error nbjm (pid=8046) NBU status: 2027, EMM status: Media server is not active Apr 26, 2025 6:13:10 AM - Error nbjm (pid=8046) NBU status: 2027, EMM status: Media server is not active Media server is not active (2027) .............. Apr 26, 2025 2:12:31 AM - Info nbdelete (pid=10762) deleting expired images. Media Server: media4003 Media: @aaaeM Apr 26, 2025 2:12:31 AM - Error nbdelete (pid=10762) Cannot obtain resources for this job : error [2027] Apr 26, 2025 2:12:31 AM - requesting resource @aaaeM Apr 26, 2025 2:12:31 AM - Error nbjm (pid=8046) NBU status: 2027, EMM status: Media server is not active Apr 26, 2025 2:12:31 AM - Error nbjm (pid=8046) NBU status: 2027, EMM status: Media server is not active Media server is not active (2027) .............. Please tell me what to do, I haven't really found any information on this error, only special cases that don't fit my case.akhimik775 days agoLevel 2187Views0likes6CommentsEvent Viewer Shows Errors TLD(0) io_open: using ndmp and Unload requested, but no unload
Hello Everyone, I got some peculiar issue with my Netbackup and this is getting worsen everyday. We have Netbackup 7.7.3 with Windows 2008 R2 64bit, using Storagetek SL500 Tape library with LTO4 Drives. This issue is the tpautoconf -report_disc shows missing device once in a every hour and again that will vanish on its own. The event viewer shows multiple errors like TLD(0) [16804] Unload requested, but no unload, drive x (xxxx 6) and TLD(0) io_open: using ndmp, this is happening for all the drives which are zoned in SAN switch. All the backups write and all the drives suddenly shows as down or down-tld. We have replaced the faulty drives, robotic arm, HBA card, Mutliple time zoning has been created at SAN switch. Network team confirmed that no issue at Network switch. Cables have been swapped but stil issue remains same. Even the NIC cards are also replaced. OS has no issues except with the Netbackup. KMA device hardware has been replaced and stil the issue remains same. I opened the case with Veritas however they say that the issue is at Hardware level, but still at what level the hardware is faulty we need to know to replace that part. Whenever we reboot tape library or power cycle the backups will run for a day or two and again the issue occurs. I am clueless at this point what else could be the issue. Your help will be greatly appreciated.koribilli129 days agoLevel 41.3KViews0likes5CommentsImage cleanup doesn't delete files
Hi, We have a problem with the Image Cleanup jobs. Each time it completes with the status "1: (1) The requested operation was partially successful." Detailed status has string "Warning bpdbm (pid=17018) nbdelete failed with status (12)" NetBackup doesn't delete files from staging folders anymore. bpdbm log file doesn't give me useful information. The only thing I see there that I think is related is: "<2> process_request: request complete: exit status 12 file open failed; query type: 72 (Q_IMAGE_DELETE)" High watermark 1%, low watermark 0% NetBackup is 10.3.0.1 All image files have ownership root:root. I tried to change user's ownership to a special account I set to run NetBackup, it didn't help. Also as far as I undersand NetBackup writes data to tapes, but just cannot clean the staging folders for some reasons. Will it be a bad idea to delete the files manually? Thank you.mfeserg10 days agoLevel 2347Views0likes4CommentsBackup of SAP HANA with multitenant database container with netbackup.
Hi, I have one query? We have netbackup 7.7.2 and SAP HANA with multitenant database container. For one instance we have to do following configurations on SAP HANA studio: Create hdbbackint soft link from /usr/sap/<SID>/SYS/global/hdb/opt/hdbbackint to /usr/openv/NetBackup/bin/hdbbackint_script for every database instance. The parameter file (initSAP.utl) must be specified for data in the SAP HANA database instance configuration. To specify the parameter file, go to Instance->Configuration-> global.ini > data_backup_parameter_file. The parameter file (initSAP.utl) must be specified for logs in the SAP HANA database instance configuration. To specify backup using the parameter file, go to Instance->Configuration->global.ini-> log_backup_parameter_file. To specify backup using the backint file, go to Instance->Configuration->global.ini-> log_backup_using_backint->SYSTEM = true. My problem is that how to configure backup for multitenant database container (For multiple Instance ) We have cluster "Dev" with multitenant database container having 3 instance "Dev" "Quality" and "SystemDB" The problem is that DBA is telling that create hdbbackint soft link from /usr/sap/<SID>/SYS/global/hdb/opt/hdbbackint to /usr/openv/NetBackup/bin/hdbbackint_script . DBA inform us that,It is not possible due to Database instances in SAP HANA database will be in hidden mode. So we cannot create the links. Requesting you to help me in this. Server Details: Master Server. Client/Master = Master NetBackup Client Platform = PC-x64, WindowsXP NetBackup Client Protocol Level = 7.7.2 Product = NetBackup Version Name = 7.7 Version Number = 770000 NetBackup Installation Path = D:\Program Files\Veritas\NetBackup\bin Client OS/Release = Windows2008 6 SAP HANA Client . Client/Master = Client of IRBIDCQCSER001.irb.local NetBackup Client Platform = Linux, SuSE3.0.76 NetBackup Client Protocol Level = 7.7.2 Product = NetBackup Version Name = 7.7 Version Number = 770000 NetBackup Installation Path = /usr/openv/netbackup/bin Client OS/Release = Linux 3.0.101-0.47.67-default1.5KViews1like1CommentHow to set notification about infected backups?
Hi All, I have implemented regular scanning of backup images. If the scan status is "Infected" I want to send a notification by e-mail. The notification could be scripted using REST API for sure. However is there any other option utilizing WebUI, Java GUI or Alta View? Thank you, Lubos17Views0likes0Comments