NetBackup IT Analytics User Guide
- Introduction
- Understand the Portal
- About the Admin tab
- Explore your inventory
- Hierarchy toolbar to organize your data
- Show objects
- Use attributes to organize your data
- Pin reports - saving reports with inventory objects
- Assign attributes in the inventory list view
- Get acquainted with reports
- About badging
- Generate and maintain reports
- Select Report Scope
- Group hosts by attributes
- Search for hosts in the report Scope Selector
- Backup Manager advanced scope selector settings
- Solution reports scope selector settings
- Units of Measure in Reports
- Customize report filter logic
- Sort columns in reports
- Convert tabular report to chart
- Distribute, share, schedule, and alert
- Scheduling Exported Reports and Dashboards
- Organize reports
- Work with the dynamic template designer
- Dynamic Template Designer Quick Start
- Converting to a Homogeneous, Product-Specific Template
- Dynamic Template Function Configurations
- Create Fields with the Field Builder
- Scope Selector Component - Custom Filter
- Configure a Bar Chart Dynamic Template
- Steps to Create a Bar Chart Dynamic Template
- Configure an Area/Stacked Area Chart Dynamic Template
- Line Charts for Performance Metrics
- Line Chart Field Requirements
- One Object Per Line Chart, One or More Metrics Per Chart
- Multiple Objects Per Line Chart, One Metric Per Chart
- Example of a Stacked Bar Chart Dynamic Template
- Create a Sparkline Chart in a Tabular Dynamic Template
- Adding or Editing Methods
- Validate and Save a Method
- Work with the SQL template designer
- Database Published Views
- Create a SQL Template
- Configure SQL Template Scope Selector Components
- Sample SQL Queries
- Configure SQL Template Scope Selector Components
- Format the SQL Template Output
- Configure a Table in the SQL Template Designer
- Advanced SQL Report Template Options
- Export/Import SQL Templates
- Pipelined functions for report query building
- APTlistOfDates
- aptStringConcat
- getServerAttributeValue
- getObjectAttributeValue
- getChildServerGroupContextById
- getServerGroupContextById
- secsToHoursMinSecs
- APTgetTapeDriveStatusName
- getFullPathname
- listJobSummaryAfterRestart
- listJobSummaryAfterRestartNBW
- listJobSummaryAfterRestart for NetWorker Backup Jobs
- listOfBackupWindowDates
- listChargebackCatByVOLSDetail
- listChargebackCatByNcVolDetail
- listChargebackCatByFSDetail (for HNAS)
- listChargebackCatByFSDetail (for EMC Isilon)
- listChargebackByLUNSummary
- listChargebackByLUNDetail
- listChargebackCatByLUNSummary
- listChargebackCatByLUNDetail
- Alert configuration
- Manage hosts, backup servers, and host groups
- Manage attributes and objects
- Provide Portal access and user privileges
- Setting / Resetting passwords
- Managing user group home pages (Administrator)
- Configure primary schedules and backup windows
- Add, edit, and move policies
- Add/Edit a threshold policy
- Capacity Chargeback policy types
- Solutions administration
- Manage and monitor data collection
- About data collection tasks
- Add/Edit Data Collectors
- Review collectors and collection status
- Upgrade Data Collectors
- Work with Capacity Manager host data collection
- Host Access Privileges, Sudo Commands, Ports, and WMI Proxy Requirements
- Host access requirements
- Manage credentials
- Configure host discovery policies to populate the host discovery and collection view
- Discovery processes
- Validate host connectivity
- Search and export in host discovery and collection
- Propagate probe settings: Copy probes, paste probes
- Discovery policies for Veritas NetBackup
- View and manage system notifications
- Customize with advanced parameters
- Use cases for advanced parameters
- Access control advanced parameters
- General Data Collection advanced parameters
- Cloud data collection advanced parameters
- Host discovery and collection advanced parameters
- Backup Manager advanced parameters
- Capacity Manager advanced parameters
- File Analytics advanced parameters
- Virtualization Manager advanced parameters
- Manage your Portal environment
- Manage ransomware scorecard
- Analyze files
- Troubleshoot the Portal
- Retrieving log files
- Debug
- Attribute inheritance overrides
- Understanding report data caching
Ransomware Scorecard overview
The Ransomware Scorecard provides a view of the preparedness of your environment with respect to ransomware resilience and recoverability. In addition, it also recommends improvements and best practices that ensure strong ransomware defense and accurate data recovery. The scorecard displays its results based on the data collected from your environment and the user responses to the evaluation queries present on the scorecard. You can also add custom queries if the default set of queries do not adequately evaluate your environment. Out-of-the-box, the scorecard derives a set of data points only from NetBackup, plus the ability to add your own custom reports for an all-round evaluation of the environment.
Follow these recommendations to ensure you get a realistic evaluation of your environment with respect to ransomware resilience and recoverability:
The higher the number of responses and data points, the more realistic is the evaluation.
Since the scorecard derives a set of data points exclusively from NetBackup out-of-the-box, ensure Veritas NetBackup Data Collector policy is configured and you have a data collection at least for a month.
Run the Ransomware Scorecard from the Ransomware folder of the Reports tab.
While setting the scope for the scorecard, choose the correct domain and select All in the other scope fields.
Initially, the Ransomware Score and Complete Queries (%) are zero. The scores start showing up as data stats are received from reports and as users post responses to the queries.
Sort the Risk column to identify the high-risk items. (The default sort order is highest risk at the top.)
The role-based access permissions and privileges available to different portal users of the Ransomware Scorecard are described below.
An administrator can set privileges and permissions for other users for the Ransomware Scorecard from Admin tab > Users > Users and Privileges > Privileges. While the Ransomware dashboard and scorecard access is controlled through Reports > Ransomware, the privileges to manage, answer, or override scorecard queries are assigned from Admin > Reports.
Table: Scorecard Roles
Role | Description |
---|---|
Ransomware Administrator or Super User | A Ransomware Administrator is expected to configure the scorecard for the organization. This role can add custom queries and disable or enable some of the built-in queries. |
User | A User can answer the queries on the scorecard and override Data type queries. Since these are two separate privilege levels, a portal administrator must enable these privileges for the user separately to allow the user to perform these actions. Both have separate privilege levels but collectively impact the total score. |
Viewer | A viewer can simply view the Ransomware Scorecard and share it outside NetBackup IT Analytics Portal through email, as HTML, PDF or other export format. Typically, a viewer is someone who is primarily interested in the results and recommendations of the scorecard. |
The above-mentioned roles translate to privileges and/or restrictions to perform the following actions. These actions are available through the Actions menu on each row of the scorecard.
Table: Role-based user privileges
User actions | Description | User privileges | ||
---|---|---|---|---|
Ransomware Administrator (Y/N) | Ransomware Answer Questions (Y/N) | Ransomware Override (Y/N) | ||
Add question Add data query | Add a new query. | Y | N | N |
Edit question Edit data query | Edit only the respective user-created query or question. | Y | N | N |
Delete | Delete only the respective user-created query or question. | Y | N | N |
Disable/Enable | Toggles between exclusion and inclusion of the data query or question in the scorecard calculation. Some default data queries or questions are mandatory and do not have this option. | Y | N | N |
Answer Question | Opens the answer form to submit a new answer or edit the previous one. This menu option appears only for Question type queries. | N | Y | N |
Answer History | Opens the answer history of a query. The report contains the answer trail of the query. This menu option appears only for Question type queries. | N | Y | N |
Item History | Shows the audit trail of the query. The report provides change history of the query as well as its responses. | Y | N | N |
Override Value | Shows the form where you can specify the override value. Override value is the percentage value by which you can offset a report-based result. You can use this option to minimize inaccuracies; however, this impacts the overall Ransomware Score. This menu option appears only for Data type queries. | N | N | Y |
Override History | Shows the trail of historical overrides of the query, including its notes. This menu option appears only for Data type queries. | N | N | Y |
Refresh | Refreshes the query result by refreshing the associated underlying report to fetch the latest figures. This menu option appears only for Data type queries. | Y | Y | Y |
More Info | If the More Info link is configured for the query, it launches the link in a new browser tab. | Y | Y | Y |
Users having access permissions to the Ransomware Scorecard, can access the it as follows:
- Select Reports > Ransomware > Ransomware Scorecard.
- Select the Domain, Query Status, Query Visibility, and Query Type from the scope selector based on the description below and click Generate.
Field
Description
Domain
Domain for which you want to create the Ransomware Scorecard
Query Status
Filters the scorecard view based on query status as follows:
All: Displays both answered and unanswered queries on the scorecard.
Completed: Displays only the answered queries on the scorecard.
Uncompleted: Displays only the unanswered queries on the scorecard.
Query Visibility
Filters the scorecard view based on its visibility status as follows:
All: Displays both enabled and disabled queries on the scorecard.
Enabled: Displays only the enabled queries on the scorecard.
Disabled: Displays only the disabled queries on the scorecard. The authority to enable or disable a query lies with the super user.
Query Type
Filters the scorecard view based on the query type as follows:
All: Displays all queries of all types on the scorecard.
Question: Displays queries of type Question on the scorecard and hides all other queries.
Data: Displays queries of type Data on the scorecard and hides all other queries.
The Ransomware Scorecard is generated based on your scope selection.
Ransomware Scorecard card components are described in the table below.
Table: Ransomware Scorecard components
Component | Description |
---|---|
Ransomware Score (%) | Ransomware score in percentage based on the user responses to the Question type queries and statistics reported by Data type queries. It is the sum of actual Score values of each query divided by the sum of maximum possible Score values of each query expressed in percentage. |
Score Trend (%) | Ransomware recoverability trend over time specified in the report scope. Mouse-over each data point to view additional details on the trend line, such as the maximum score, percentage score, impacting query, and event. |
Completed Queries (%) | Indicates the extent to which the ransomware preparedness evaluation is complete in percentage. A higher percentage reflects a better overall score. |
Type | Indicates whether the query type is a Question or a Data input received from reports. |
Query | The actual query text. |
Result | Responses received from users or values derived from associated reports. |
Best Practice Recommendation | Standard best practices recommended for the respective query. These are hidden until the user answers the query. |
Score | Indicates the quality of the response submitted for the query. It is the sum of individual scores multiplied by the weight of the query. |
Risk | Indicates the extent of risk associated with the query based on the submitted answer. Low or Lowest score for a query with high Weight results in high Risk and is represented by a longer bar. Significant risk is indicated with an added triangle next to the bar. |
The Ransomware Scorecard provides a history view of the following components:
Answer History: Displays the historical responses received for a query of type Question. The history contains details such as Answer (user response), Deleted (Yes/No), Event, Notes as added by the user, and the name of the users who modified the query.
Override History: Displays the history of override action performed by the user on the query. The history contains details such as Event, Notes, Modified by, and Modification date of the override.
Item History: Displays the change history of the query and also its responses. The report details include the trail of edits made to the query and another table that displays a trail of changed responses over time. Each detail is captured with its time stamp.