Splunk SOAR

Backing up for upgrade

alexander5654
New Member

Hi, my team is preparing to upgrade our phantom instance to the newest version, and I had a question regarding the backup before the update.

When I create the backup using the ibackup.pyc file, can i use that restore for a later version?

Just also making sure my understanding is correct, is all data deleted during the upgrade, or is the backup just done in case an update messes with things and allows you to restore to your previous, un-upgraded state?

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@alexander5654 the restore will restore the entire platform state rather than just the data. Therefore it can't be used to restore to to a later version.

No data is deleted upon upgrade but a backup should be taken for any disaster type situation where a restore would be needed to a valid and recent point in time, as you alluded to in your question. 

If this helps, please mark as a solution & happy phantoming!

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---

aocvy
Engager

What's the link to the backup documentation? 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@aocvy Please find the docs here: https://docs.splunk.com/Documentation/SOARonprem/5.1.0/Admin/BackupTools 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...