Backup and restore
To recover from any data loss that might occur, regularly back up your IBM® Security QRadar® EDR data. You can use the backup and restore process to support a disaster recovery that requires a redeployment of your environment.
When you install QRadar EDR, you configure a suitable storage class in the cluster. You support the configuration with one or more persistent volumes of suitable size. For more information about storage, see Storage requirements.
You provide secure storage for the backups that is mounted as a Persistent Volume Claim (PVC) in a pod. The backup and restore pod contains all of the necessary utilities for the backup and restore process. The backup and restore pod is deployed automatically as part of the installation or upgrade of QRadar EDR. By default the last 10 backups are kept for each data store.
The following table shows where the backup files are stored in the backup and restore pod, and the backup file name convention that is used for each data store.
Data store | Location | Backup file name |
---|---|---|
Cassandra | /opt/data/backup/cassandra | cassandra_backup_<YYYY_MM_DD__HH_MM_SS>.gz |
Elasticsearch | /opt/data/backup/elasticsearch | elasticsearch_backup_<YYYY_MM_DD__HH_MM_SS>.gz |
QRadar EDR | /opt/data/backup/reaqta | reaqta_backup_<YYYY_MM_DD__HH_MM_SS>.gz |
Postgres | /opt/data/backup/pg | pg_backup_default_<YYYY_MM_DD__HH_MM_SS>.gz |