cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8288
Views
10
Helpful
5
Replies

How to backup the database in stealthwatch?

jose.guzman
Level 1
Level 1

Hello,

 

Has anyone backed up the database in stealthwatch version 7.0?

 

I want to back up the database on my computer, but trying to test the connectivity with the remote system gives me the following error

 

stealth.PNG

 

On my computer I enabled SMB, I gave administrator permissions to the account and to the folder where I expected to save the backup.

Does anyone have a step by step how to backup the stelathwatch database? or someone has done it before? I can not configure the remote system to store the database

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

LaminadT
Level 1
Level 1

I also have the same issue trying to backup to a Windows Server configured with an SMB shared folder. I can modify the share via powershell using the account I created, but I get the same permission denied error in the Stealthwatch console.

 

smb_powershell_example.PNGsmb_stealthwatch_example.PNG

 

Edit:

 

I have now also tried via the root shell and the mounting process failed for the same reason as well. I also noticed that Stealthwatch is not putting the mount drive in the /etc/fstab file, but it may only add it to the file once the mount is successful.

 

smb_root_shell_example.PNG

 

fstab.PNG

 

Edit2:

 

I manually added the share to the etc/fstab file and now I no longer get a permission denied error, but get a mount error(5): Input/output error. Some possible reasons for that error are either the CIFS version or the NTLM version that are being used. I have tried manually setting those options in the mount process as well, but I just get an invalid argument error from the SMC root shell when those options are added.

 

fstab_with_share_drive.PNGsmb_root_shell_example_post_fstab.PNG

 

Edit 3:

 

So I worked with TAC and determined the issue. Right now Stealthwatch only allows SMBv1, but most modern servers will only accept SMBv2 or greater by default. So the solution is to either configure the server to accept SMBv1, or to modify the /lancope/admin/lib/RunTime.py file to use a different version of SMB.

 

stealthwatch_runtime.jpg

View solution in original post

5 Replies 5

LaminadT
Level 1
Level 1

I also have the same issue trying to backup to a Windows Server configured with an SMB shared folder. I can modify the share via powershell using the account I created, but I get the same permission denied error in the Stealthwatch console.

 

smb_powershell_example.PNGsmb_stealthwatch_example.PNG

 

Edit:

 

I have now also tried via the root shell and the mounting process failed for the same reason as well. I also noticed that Stealthwatch is not putting the mount drive in the /etc/fstab file, but it may only add it to the file once the mount is successful.

 

smb_root_shell_example.PNG

 

fstab.PNG

 

Edit2:

 

I manually added the share to the etc/fstab file and now I no longer get a permission denied error, but get a mount error(5): Input/output error. Some possible reasons for that error are either the CIFS version or the NTLM version that are being used. I have tried manually setting those options in the mount process as well, but I just get an invalid argument error from the SMC root shell when those options are added.

 

fstab_with_share_drive.PNGsmb_root_shell_example_post_fstab.PNG

 

Edit 3:

 

So I worked with TAC and determined the issue. Right now Stealthwatch only allows SMBv1, but most modern servers will only accept SMBv2 or greater by default. So the solution is to either configure the server to accept SMBv1, or to modify the /lancope/admin/lib/RunTime.py file to use a different version of SMB.

 

stealthwatch_runtime.jpg

LaminadT thank you, thank you, thank you. This was driving me insane. Editing /lancope/admin/lib/RunTime.py, searching vers=1.0 and changing it to 2.1 did the trick.

Hi htejedaMFB,

I have also the same problem occur during the up-gradation. Currently in my network the device is running on 6.10.5 IOS version and we want to upgrade the latest 7.1. But at the database backup point In the Remote file system i have no idea what type of server is used and how much storage is required?
Please Give me a step by step solution for the same.

Thanks
Manish Kumawat

This is an update on this issue.  Trying to backup 7.3.2 before upgrade to 7.4.1 and the issue has returned. Probably in one of the previous upgrades the files changed. Called TAC and there is a new location and file. Enable SSH on SMC/FC and SSH into them. The location is /lancope/admin/lib/system.d/disk and the file name disk.py.   Search for mount.cifs and change the vers=1.0.  I changed it to 2.1 and I'm back in business.

Screenshot 2022-07-15 132001.jpg

Hi LaminadT,

I have also the same problem occur during the up-gradation. Currently in my network the device is running on 6.10.5 IOS version and we want to upgrade the latest 7.1. But at the database backup point In the Remote file system i have no idea what type of server is used and how much storage is required?

Please Give me a step by step solution for the same.

Thanks
Manish Kumawat