Showing posts with label Troubleshooting. Show all posts
Showing posts with label Troubleshooting. Show all posts

How to improve performance when taking backup to cloud storage pools (hybrid cloud backup) - Video tutorial

Since IBM now supports various cloud storage services to take the backups, you can use cloud container storagepools to store both the deduplicated data and non-deduplicated data and restore the data as required.  Starting from IBM Spectrum Protect  (TSM) V 7.1.7, you can configure cloud-container storage pools on 4 of the popular and widely used cloud based object storage systems to backup the data. However, the backup performance of a cloud-container storage pool largely depends on the network connections between the server and the cloud. Sending data to cloud storage requires good network bandwidth along with the advanced security features. But most of the small and medium sized organisations cannot afford to buy the high network bandwidths if they want to use cloud as the storagepool destinations. 

To address this situation, IBM has introduced a new hybrid and optimised data transfer techniques. You can now define local storagepool directory by using the new DEFine STGPOOLDIRectory command where the data is stored temporarily before it is transferred to the cloud. This technique is generally referred as hybrid cloud backup. This hybrid cloud backup feature will help you to set up local storage for data that is later moved to the cloud. By assigning one or more local storage directories to a cloud-container storage pool, you can enhance the performance of backup operations to the cloud. When you back up the data to local storage, the data is buffered efficiently into disk containers and moved to the cloud as larger objects. With larger objects, you can achieve better performance results. Use this command to define one or more directories in a directory-container or cloud-container storage pool.
How to improve backup performance when taking backup to cloud storage pools

For Example: define stgpooldirectory pool1 /storage/dir1,/storage/dir2

When you define a local storage directory, data is temporarily stored in the directory during data ingestion, and is then moved to the cloud. you can set up local storage for data that is later moved to the cloud. By assigning a local storage directory to a cloud-container storage pool, you can enhance the backup performance of small objects, for example, client-transaction data.


After you define a cloud-container storage pool, create one or more directories that are used for local storage. You can temporarily store data in local storage during the data ingestion, before the data is moved to the cloud. In this way, you can improve system performance. 

Watch the below video on how to configure cloud services to configure hybrid cloud backups in 3 simple steps by using IBM Spectrum Protect and Amazon S3.

How to configure storage pool on a Cloud Storage services - Video tutorial

Starting from IBM Spectrum Protect  (TSM) V 7.1.7, you can configure cloud-container storage pools on 4 of the popular and widely used cloud based object storage systems to backup the data. IBM supports the following cloud based object storage systems to configure storagepools and to take backup of the clients and to improve server performance, simplify storage management, and secure data by using encryption.
  • Amazon S3
  • Cleversafe
  • IBM SoftLayer
  • OpenStack Swift
You can use cloud container storagepools to store both the deduplicated data and non-deduplicated data and restore the data as required. However, before configuring the cloud container storage pool, you need to get the required account information details of the cloud environment which you want to use as the destination.

Also Read: What is Cloud Container Storagepool ?

Cleversafe
If you want to configure cloud-container storage pools on Cleversafe, you must first set up a Cleversafe vault template and a Cleversafe user account, and then obtain the below configuration information.
  • CLOUDTYPE: S3
  • IDENTITY: access_key_ID
  • PASSWORD: secret_access_key
  • CLOUDURL: http://cleversafe_accesser_IP_address
Cleversafe vaults are used in the same manner as containers in a cloud-container storage pool. Set up a Cleversafe vault template to quickly create vaults with your preferred settings. After you create a vault template, use the credentials from your Cleversafe user account to configure the storage pools in the Operations Center or with the DEFINE STGPOOL command. Tivoli Storage Manager uses the Simple Storage Service (S3) protocol to communicate with Cleversafe.

Amazon S3
If you want to use Amazon Simple Storage Service for cloud container storage pool, you must obtain information from Amazon that is required for the configuration process. Amazon S3 uses buckets to store data. Amazon S3 buckets are used in the same manner as containers in a cloud-container storage pool. Tivoli Storage Manager automatically creates a bucket in Amazon for an instance of Tivoli Storage Manager, and that bucket is shared by all pools for that instance.
  • CLOUDTYPE: S3
  • IDENTITY: access_key_id
  • PASSWORD: secret_access_key
  • CLOUDURL: Specify the region endpoint URL that best fits your location, based on the Amazon AWS Regions and Endpoints page.
OpenStack Swift
Similarly if you want to use OpenStack Swift, you must obtain configuration information from the OpenStack Swift computer. Use the credentials from your OpenStack Swift account when you configure the storage pools by using the Operations Center or the DEFINE STGPOOL command.
  • CLOUDTYPE: SWIFT or V1SWIFT
  • IDENTITY: OS_TENANT_NAME:OS_USERNAME
  • PASSWORD: OS_PASSWORD
  • CLOUDURL: OS_AUTH_URL
IBM SoftLayer
Similarly, if you use IBM SoftLayer, you must obtain configuration information from the SoftLayer Object Storage page. Use the credentials from your SoftLayer account when you configure the storage pool.
  • CLOUDTYPE: SOFTLAYER
  • IDENTITY: username
  • PASSWORD: API_key
  • CLOUDURL: public_authentication_endpoint

How to configure cloud container storage pool

Once you have the above required information, you can configure the cloud container storage pool by using both Operations Center and the command-line interface. However, the preferred way to define and configure a cloud-container storage pool is to use the Operations Center as it will be easier to configure and manage. Please watch the below video to understand how to do this. 

Also Read: How to restore damaged files in a primary storagepools from replication server automatically

If you want to do it in a command line, use DEFINE STGPOOL command to configure cloud container storagepool in a cloud services platform.
How to configure cloud container storage pool

CLOUDType parameter specifies the type of cloud environment where you are configuring the storage pool. You can specify any one of the following values explained above. If you define a storage pool as using S3 with this parameter, you cannot later change the storage pool type by using the UPDATE STGPOOL command. If you do not specify the parameter, the default value SWIFT will be used.
CLOUDUrl specifies the URL of the cloud environment where you are configuring the storage pool. 
IDentity specifies the user ID for the cloud that is specified in the STGTYPE=CLOUD parameter. Based on your cloud provider, you can use an Access Key ID, a user name, a tenant name and user name, or a similar value for this parameter. 
PAssword specifies the password for the cloud that is specified in the STGType=CLoud parameter. Based on your cloud provider, you can use a Secret Access Key, an API Key, a password, or a similar value for this parameter.
CLOUDLocation specifies the physical location of the cloud that is specified in the CLoud parameter. You can specify OFFPREMISE or ONPREMISE if you have your own cloud setup. The default value is OFFPREMISE.
BUCKETName pecifies the name for an S3 bucket or a Cleversafe vault to use with this storage pool, instead of using the default bucket name or vault name. This parameter is optional, and is valid only if you specify CLOUDTYPE=S3

For example
define stgpool cloud_stg stgtype=cloud cloudtype=softlayer cloudurl=http://123.456.789:5000/ identity=admin:admin password=password 

Please watch the below video to configure cloud container storagepool on Amazon S3 platform by using operations center. You can use the same steps for other cloud platforms as well.

Follow these 10 tips to secure your IT backup infrastructure (Spectrum Protect)

Today, most of the IT data centres are affected by the modern and intelligent malware and viruses in some or the other form. This can be due to the negligence of the employees or inappropriate security systems that are implemented. Currently we have a new type of data theft strategies such as  RasomWare implemented by cyber attackers to steal the business critical information. This RasomWare cyber attack, have plagued many of the todays organizations inspite of the stringent security policies.

These attacks have prompted 90% of the organizations to review the way that their data protection infrastructure is managed, and to look at how they can secure their backup environments even further. And also as a backup specialist, we should also take extra care to make sure the data which is backed-up to tape or to the cloud is secure enough from the modern day cyber attacks. 

Also Read: Use these 3 methods to fix the slow and long running incremental or full backups 

To address these kind of cyber attacks, IBM recommends the below 10 security tips to implement in your backup infrastructure to prevent data theft in any form. The below video from IBM Spectrum Protect storage specialist describes the current exposure many organizations backup solutions have, and discusses methods to reduce their security exposure. It proposes solutions to further protect the data protection core components so they, themselves, are not destroyed along with the primary data.

The below video will cover how to:
  • Harden the Spectrum Protect server hosts

  • Protect Spectrum Protect servers against RansomWare and other Malware
  • Secure the communication pathways
  • Secure Spectrum Protect administration 
  • Secure Spectrum Protect client nodes
  • Use all support and alerting tools available to you and apply Flashes
  • Follow strong testing and currency policies
  • Validate Data Protection and DR Services
  • Make the Protect Server infrastructure easier to manage reliably
  • Make the Protect Clients easier to manage reliably
The below video also covers how the security settings are configured in many TSM servers today and the different types of Security models offered by IBM Spectrum Protect which can be implemented in your backup setup.

Also Read: IBM Spectrum Protect V8 new features

How to repair damaged data on the directory-container storage pool on a target server

IBM has introduced new set of commands to easily repair the damaged data on the directory-container storage pool on both source and target TSM servers when you enable replication techniques. By using these commands you can save lots of time and money which we spend on recovering the damaged storage pools earlier. You can use PROTECT STGPOOL, AUDIT CONTAINER and REPAIR STGPOOL commands to repair the damaged data on the directory-container storage pool on the target TSM servers. 

The repairing process of the directory-container storage pool  on the target server is done automatically by using the above commands. If the damaged data extent was backed up on a directory-container storage pool on the target server, you can repair the data extent manually by using the REPAIR STGPOOL command. Information about what is repaired is recorded in the activity log for the target server. However, the automatic repair process has the following limitations:
  • Both the source server and the target server must be at V7.1.5 or later.
  • To be repaired, extents must already be marked as damaged on the target server. The repair process does not run an audit process to identify damage.
  • Only target extents that match source extents are repaired. Target extents that are damaged but have no match on the source server are not repaired.
  • Extents that belong to objects that were encrypted are not repaired.
  • The timing of the occurrence of damage on the target storage pool and the sequence of REPLICATE NODE and PROTECT STGPOOL commands can affect whether the repair process is successful. Some extents that were stored in the target storage pool by a REPLICATE NODE command might not be repaired.

So to repair the damaged data, you need to first find out what is the damaged data in the target storage pool. To identify the damaged data, we use AUDIT CONTAINER command and QUERY DAMAGED commands. The AUDIT CONTAINER command is used to scan for inconsistencies between database information and a container in a directory-container storage pool. Whereas QUERY DAMAGED command is used to display information about damaged data extents in a directory-container or cloud-container storage pool. Use this command together with the AUDIT CONTAINER command to determine a recovery method for the damaged data.

Steps to follow to repair damaged data on the directory-container storage pool on the Target server

Step 1: Verify the consistency of database information for a directory-container on the target TSM server

Use AUDIT CONTAINER  command to scan for inconsistencies between database information and a container in a directory-container storage pool. You can use this command to complete the following actions for a container in a directory-container storage pool
  • Scan the contents of a container to validate the integrity of the data extents
  • Remove damaged data from a container
  • Mark an entire container as damaged


You can Specify the name of the container or the the name of the directory-container storage pool or the  name of the container storage pool directory that you want to audit.  For example, to mark as damaged all of the data in a directory-container storage pool
audit container stgpool=prdpool maxprocess=5 action=markdamaged

Also you can specify the type of action to be performed when using this command by using Action parameter. It specifies what action the server takes when a container in a directory-container storage pool is audited. It has the following options
SCANAll - Specifies that the server identifies database records that refer to data extents with inconsistencies. This value is the default. The server marks the data extent as damaged in the database.
REMOVEDamaged - Specifies that the server removes any files from the database that reference the damaged data extent.
MARKDamaged - Specifies that the server explicitly marks all data extents in the container as damaged.
SCANDamaged - Specifies that the server checks only the existing damaged extents in the container.


If the audit does not detect an error with a data extent that is marked as damaged, the state of the data extent is reset. The data extent can then be used. This condition provides a means for resetting the state of damaged data extents if errors are caused by a correctable problem. The SCANALL and SCANDAMAGED options are the only options that reset a damaged extent if it is found not to be damaged.

Step 2: Query damaged data in a directory-container or cloud-container storage pool - optional

Use QUERY DAMAGED command to display information about damaged data extents in a directory-container or cloud-container storage pool. Using this command together with the AUDIT CONTAINER command will help you to determine a recovery method for the damaged data.
For example, to display status information about damaged or orphaned data extents
query damaged prdpool type=status

Storage Pool     Non-Deduplicated          Deduplicated   Cloud Orphaned   Name             Extent Count                     Extent Count      Extent Count  ---------------         -------------                           ----------             -------------POOL1                  65                                       238                     18

Use the Type parameter to specify the type of information to display. You can use the following options
Status - Specifies that information is displayed about damaged data extents. For cloud storage pools, orphaned extents are also displayed. This is the default.
Node Specifies that information about the number of damaged files per node is displayed.
INVentory - Specifies that inventory information for each damaged file is displayed.
CONTAiner - Specifies that the containers that contain damaged data extents or cloud orphaned extents are displayed. For directory-container storage pools, storage pool directories are also displayed.
Nodename - Specifies that damaged file information for a single node is displayed.

Step 3: Automatic Repair of damaged extents 

Starting from Tivoli Storage Manager Version 7.1.5, when a storage pool protection process runs for a directory-container storage pool on a source server, damaged extents in the target server's storage pool are repaired automatically. 

You can check the information about what is repaired is recorded in the activity log for the target server once the storage pool protection process gets completed. Ideally it is recommended to schedule the step 2 and step 3 in regular intervals so that the damaged data extents are automatically repaired during daily storagepool protection process.

How to repair damaged data on the directory-container storage pool on a source server

IBM has introduced new set of commands to easily repair the damaged data on the directory-container storage pool on both source and target TSM servers when you enable replication techniques. By using these commands you can save lots of time and money which we spend on recovering the damaged storage pools earlier. You can use PROTECT STGPOOL, AUDIT CONTAINER and REPAIR STGPOOL commands to repair the damaged data on the directory-container storage pool on both source and target TSM servers. 

Infact, the repairing process of the directory-container storage pool  on the target server is done automatically by using the above commands. In this post we will see the steps to repair damaged data on the directory-container storage pool on a source server.

Steps to follow to repair damaged data on the directory-container storage pool on a source server

Step1: Enable protection manually or automatically

You can protect the storagepools by configuring automatic protection or manual protection. 
To enable storagepool protection automatically, specify the PROTECTSTGPOOL parameter on the DEFINE STGPOOL or UPDATE STGPOOL command to back up the data. For example
update stgpool prodpool protectstgpool=proddrpool

To enable storagepool protection manually, use PROTECT STGPOOL command to protect data in directory-container storage pools by storing the data in another directory-container storage pool on the target server. When you issue this command, data that is stored in the directory-container storage pool on the source server is backed up to a directory-container storage pool on the target server. You should issue this command on the server that is the source server for data.
How to repair damaged data on the directory-container storage pool on a source server

For example to protect a storage pool to a target replication server
protect stgpool devpool maxsessions=5

Use the FORCEREConcile parameter to specify whether to reconcile the differences between data extents in the directory-container storage pool on the source server and target server. If you specify NO to this option, the data backup does not compare all data extents in the directory-container storage pool on the source server with data extents on the target server. Instead, data backup tracks changes to the data extents on the source server since the last backup and synchronizes these changes on the target server. If you specify YES, the data backup compares all data extents on the source server with data extents on the target server and synchronizes the data extents on the target server with the source server.

Step 2: Repair the storagepool by using REPAIR STGPOOL command

If you notice any damage of data on the source storagepool, you can repair the storagepool by using REPAIR STGPOOL command


By protecting the directory-container storage pool, you can repair damaged storage pools by using the REPAIR STGPOOL command. It is used to repair deduplicated extents in a directory-container storage pool. Damaged deduplicated extents are repaired with extents that are backed up to the target server. 
repair stgpool command

For example, to repair a storage pool 
repair stgpool devpool maxsessions=5

You must issue the PROTECT STGPOOL command to back up data extents to the directory-container storage pool on the target server before you issue the REPAIR STGPOOL command. The REPAIR STGPOOL command fails when any of the following conditions occur:
  • The target server is unavailable.
  • The target storage pool is damaged.
  • A network outage occurs.

Limitations of enabling compression on TSM DB backups

Deduplication and replication techniques are server intensive processes and if you enable these techniques, you might additionally notice that your TSM DB size has been increased rapidly. If you are taking DB backups on a FILE or SERVER device class, it is obvious that you might require additional space to store the multiple versions of DB backups. This situation costs lots of disk space for the organizations and it might necessary to store the DB backups on disks if you have stringent recovery times. 

So in this kind of situations, you can enable compression when taking TSM DB backups.  By compressing volumes that are created during database backups, you reduce the amount of space that is required for your database backups.

How to enable compression for TSM DB backups

You can enable compression while running BACKUP DB command manually or you can enable the compression setting for all the DB backups by using SET DBRECOVERY command. For example, to enable compression for a full DB backup taking on to FILE device class
backup db devc=FILE type=full compress=yes


And the syntax for enabling compression for all backups automatically is


By default, the compress value is NO as shown above. You need to specify YES, to enable compression automatically for all DB backups. If you specify the COMPRESS parameter on the BACKUP DB command, it overrides any value that is set in the SET DBRECOVERY command. Otherwise, the value that is set in the SET DBRECOVERY command is the default.

Also Read: Taking TSM server DB backup when the server is down

Limitations of enabling compression during DB backup

  • This feature is valid only if you are planning to take DB backup on to a disk storage, generally FILE device classes. 
  • Using compression during database backups can reduce the size of the backup files. However, compression can increase the time that is required to complete database backup processing.
  • Also, it might take extra time to decompress the DB backup files during TSM DB restore. This will put additional pressure if it is a disaster recovery situation. The whole purpose of this setting is to save storage space only, not to increase DB backup performance.
  • Do not back up compressed data to tape. If your system environment stores database backups on tape, set the COMPRESS parameter to No in the SET DBRECOVERY and BACKUP DB commands.