This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Questions on re-installing NMP-SAM-NQP-Netflow with version 2020.2.4

I am not able to power my 2020.2.1 servers back up but I do still have the database available as it was on 12/14. Does anyone know if the database was hacked in any way and would it be save to bring back online with new servers? Or do I need to start from scratch and build out new databases for NPM and Netflow? If the database is safe to use would it be possible to install 2020.2.4 onto my servers and attach directly to it?

What have others done to restore their system?

  • Hi bobmarly 

    What do you mean you are not able to power the servers up? Why. is there a hardware fault? 

    Regards

  • The servers are running an unpatched version and we were directed to power them off by our Security Team. 

  • Hi that’s more of a question for you and your security team to determine and weigh the risks. I would run this by them for their input (my 2 cents...)

    Ultimately what it would come down to for me is risk vs reward... e.g. I would prefer to use the existing database if I had a complex multi-module environment and it would not be easily rebuilt from the ground up. However if my node count was low and complexity far and few then what would the benefit be if the time to reconfigure everything would not take long?

    Either way I would recommend building a brand new database server and restore from backup the database and at the very least recycling all accounts/passwords.

    Best of luck in your decision!
  •  

    Thanks! I think I'm going to spin up a new server, attach to the database long enough to export all of the alerts, custom pollers, and reports and then retire the server and DB then start from scratch with new servers and databases. 

  • I am running it by our Security Team and our Management this week. The current installations has four years of customizations in it so I would hate to lose all that work and have to rebuild it from scratch. Lessons learned though if I'm able to get it running again is to create daily exports of all custom properties, alerts, and reports, etc.