NetBackup IT Analytics Data Collector Installation and Configuration Guide for Veritas NetBackup
- Introduction
- Configure a NetBackup IT Analytics Distributed Data Collector on a NetBackup Primary Server
- Configure Data Collector on non-clustered NetBackup 10.4 and later primary server
- Configure Data Collector on non-clustered NetBackup 10.1.1, 10.2, 10.2.01, 10.3 or 10.3.0.1 primary server
- Configure a Veritas NetBackup Data Collector Policy
- Configuring file analytics in NetBackup Data Collector policy
- Installing the Data Collector software
- Configure SSL
- Centralized Data Collector for NetBackup - Prerequisites, Installation, and Configuration
- Step-1: Choose operating system and complete prerequisites
- Step-5: SSH/WMI
- Upgrading Data Collector Locally
- Clustering Data Collectors with VCS and Veritas NetBackup (RHEL)
- Clustering Data Collectors with VCS and Veritas NetBackup (Windows)
- Install and configure NetBackup IT Analytics Data Collector on MSCS environment
- Data Collector Policy Migration
- Pre-Installation setup for Veritas NetBackup appliance
- Pre-installation setup for Veritas Flex Appliance
- Data Collector Troubleshooting
- Host resources: Check host connectivity using standard SSH
- Host resources: Generating host resource configuration files
- Configuring parameters for SSH
- Appendix A. Configure Appliances
- Appendix B. Load historic events
- Load Veritas NetBackup events
- Appendix C. Firewall configuration: Default ports
- Appendix D. CRON Expressions for Policy and Report Schedules
- Appendix E. Maintenance Scenarios for Message Relay Server Certificate Generation
Regenerate authentication certificate nearing expiry (or already expired)
Data exporters and data senders, installed on the hosts from where data is collected, require certificates to establish authentic communication with message relay server and data sender installed on the data collector system. This section provides the procedure to regenerate such a certificate that has either expired or is nearing expiry.
To regenerate a certificate:
- Login to the data collector system and navigate to its installation path:
/aptare/mbs/conf
. - Identify these files inside
/aptare/mbs/conf
:aptare_message_relay_certificate.pem
aptare_message_relay_keystore.ks
aptare_message_relay_keystore.properties
- Stop the Aptare Agent service on the data collector system.
On a Windows system, you can stop the service from the Services Console, whereas you can use ./aptareagent stop command on Unix.
- Delete
aptare_message_relay_certificate.pem
andaptare_message_relay_keystore.ks
files from/aptare/mbs/conf
. - Start the Aptare Agent service on the data collector system.
The
aptare_message_relay_certificate.pem
andaptare_message_relay_keystore.ks
files are regenerated and will reappear inside the/aptare/mbs/conf
folder.The data collector sends a REST request to the data receiver and publishes the new certificate in the database. The certificate is essential to enable communication between the message relay server and the data sender trust store. Hence, you must download the new certificate as described in the steps below and copy it to all the data senders.
To download the new certificate:
- Login to the NetBackup IT Analytics Portal.
Since the certificate was changed, the portal will display a notification which states:
Data Collector SSL certificate has not been downloaded for collector(s): <data_collector_name>.
- Go to Admin > Data Collection > Collector Administration and click the collector name to view its policies.
- Double-click the policy name for which SSL certificate needs to be downloaded. The policy configuration window is displayed.
- Click Download SSL Certificate. The certificate is downloaded to your system.
- Copy the certificate to the data sender trust store.