Previous Topic: Verify RestorationNext Topic: Configure Max Archive Days for Restored Archives


Manually Restoring Archives to a New Event Log Store

You may occasionally need to restore cold stored files for querying or reporting, as for an annual or semi-annual compliance audit. If you designate one CA User Activity Reporting Module to act as a restore point for investigations on cold data, you must force a rebuilding of the catalog each time you restore a new database to this CA User Activity Reporting Module. A rebuilding of the catalog, or recatalog, is required only when restoring data to a different server than the one on which it was generated.

Important! Ensure the Max Archive Days setting for this server's event log store is adequate. Otherwise, restored files are immediately deleted.

A recatalog is automatically performed when iGateway is restarted, if needed. If databases were incompletely cataloged before iGateway was shut down, the recataloging process completes when iGateway is restarted. If one or more databases are added to the archive database directory while iGateway is down, the recatalog process is performed at the next startup of iGateway.

Restoring archived files from external storage to a different CA User Activity Reporting Module from where they were backed up involves the following steps:

  1. Identifying the databases that you want to restore. For help, query the archive catalog with filters.
  2. Moving the identified cold archive files from external storage to your network.
  3. Copying the moved databases to the archive directory. To display the archive directory, run the LMArchive utility with the -list loc option.
  4. Rebuilding the archive catalog (recatalog).

    Rebuilding the archive catalog to add a single database can take several hours. After waiting long enough for the recatalog process to complete, you can begin your investigation by running queries and reports on the event logs from the restored databases.

  5. Verify restoration by issuing a query.

Note: If you dedicate a CA User Activity Reporting Module as restore point, be sure to exclude it from the federation.

More information:

Move Archived Databases to an Archive Directory

Configure Max Archive Days for Restored Archives

Add Restored Databases to the Catalog

Verify Restoration

Example: Allow a Non-Administrator to Manage Archives