This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
Announcement Banner

The email address for NetWitness Community notifications is changing

View Details
  • NetWitness Community
  • Discussions
  • Re: Upgrade RSA SA to NetWitness - Backup and Migration
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Upgrade RSA SA to NetWitness - Backup and Migration

VishamRawat
VishamRawat Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 06:53 AM

Just want to confirm a couple of points, and hopefully I have the right understanding!

 

The Backup process for upgrading RSA SA 10.6.6 to RSA NetWitness 11.3 basically captures all the configuration for all RSA SA servers. This configuration information includes IP, subnet and other network and other information as well, right?

 

Now, once the 11.3 VM is setup, we migrate the HDDs of the corresponding 10.6.6 VM to the 11.3 VM, which basically means we're migrating all the log and meta data from the 10.6.6 VM to the 11.3 VM, right? So, for instance if I migrate the 10.6.6 VM HDDs of the Archiver to the 11.3 Archiver, I shall have all the logs and meta available on the new 11.3 Archiver machine, correct?

 

Additionally, after we've setup the VM, and before running nwsetup-tui we restore the backed up configuration on the VM, which should assign the same network (including IP and subnet) and other info to the new 11.3 VM, as was assigned to the corresponding old 10.6.6 VM, right?

 

Please let me know if I've got this understanding right!

  • Community Thread
  • Discussion
  • Forum Thread
  • netwiness
  • NetWitness
  • netwitness-logs
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
  • rsasa
  • sa
  • sa upgrade
  • Version 11.3
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
5 REPLIES 5

AaronMartin2
Employee AaronMartin2
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 09:35 AM

The Backup process for upgrading RSA SA 10.6.6 to RSA NetWitness 11.3 basically captures all the configuration for all RSA SA servers. This configuration information includes IP, subnet and other network and other information as well, right?

Correct. Like you noted here, it's primarily config with the exception of the ESA Alerts/Incidents. This is because these are inside of mongo and we back up the entirety of the mongo databases. This is the only thing that I remember is self contained in the backup that is created by the script. The rest of the collected data, as you already stated, is covered in your next question.

Now, once the 11.3 VM is setup, we migrate the HDDs of the corresponding 10.6.6 VM to the 11.3 VM, which basically means we're migrating all the log and meta data from the 10.6.6 VM to the 11.3 VM, right? So, for instance if I migrate the 10.6.6 VM HDDs of the Archiver to the 11.3 Archiver, I shall have all the logs and meta available on the new 11.3 Archiver machine, correct?

Also correct. This is where you would migrate your metadb, sessiondb, and packetdb files of all core devices. Core devices being Decoders, Concentrators, Brokers, and Archivers.

Additionally, after we've setup the VM, and before running nwsetup-tui we restore the backed up configuration on the VM, which should assign the same network (including IP and subnet) and other info to the new 11.3 VM, as was assigned to the corresponding old 10.6.6 VM, right?

This is correct. Please do not attempt to change IP information while doing this upgrade as the IP information is scattered throughout the config files themselves, not just the CentOS network scripts. Conducting this change is unsupported and I can promise you is no fun to deal with.

 

You are free to change IP information after the upgrade has been completed as we have a process in the 11.3 Administration Guides.

1 Like
Share
Reply

VishamRawat
VishamRawat Beginner
Beginner
In response to AaronMartin2
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 09:38 AM

Thanks Aaron

0 Likes
Share
Reply

AaronMartin2
Employee AaronMartin2
Employee
In response to VishamRawat
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 09:40 AM

No problem!

0 Likes
Share
Reply

JohnSnider
Trusted Contributor JohnSnider Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 10:24 AM

AS a note, the migration backup scripts are designed to migrate the end device vm "in-place", (i.e. not moving to a "new" vm), you would run the backups with the "-u" option and it will place a copy of the backups back out on the device being backed up.  you then boot to the 11.3 iso on that device and and install 11.3 (do not clear the disk configurations when asked), it will remove all partitions except anything in /var/netwitness (where the backup are located) and then install centos 7 and the basic install files, when you run "nwsetup-tui" you will select the upgrade mode and it will use then information in the backup to set the IP and other information on the host.  after discovery and installation of the proper services, the host will be the same as it was before and the data drives should be mounted as they were on the old host, with no loss.

 

If you decide to go the route of creating a new VM for each on, you will have to manually copy the backup files to the proper location on the host BEFORE running the nwsetup-tui, and you will still be doing the upgrade, so adding the extra step is just complicating things.

0 Likes
Share
Reply

VishamRawat
VishamRawat Beginner
Beginner
In response to JohnSnider
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-08-30 11:19 AM

Hi John,

 

Just to clarify, I simply follow the procedure given in the RSA Upgrade Guides for Virtual Host 10.6.6 to 11.3, and it should be good right? It speaks of deploying 11.3 via a OVF Template and then moving the HDDs, etc. It has visuals for the steps, so I can follow that smooth, right?

0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.