
Summary
This detection rule is designed to identify hosts within an enterprise environment that have not successfully completed a backup within the last seven days using the NetBackup system. The underlying search command analyzes logs filtered for the specific message indicating successful completion of backups. It utilizes statistical functions to determine the latest successful backup time for each host and evaluates whether that time exceeds the specified threshold of one week. If a host's latest backup time is older than seven days, it categorizes that host as an outlier and presents the relevant data in a structured table format. Due to its reliance on infrastructure monitoring and the adoption of other more effective solutions, this rule has been marked as deprecated. Consequently, users are encouraged to consider alternate approaches for monitoring backup efficacy.
Categories
- Infrastructure
- Endpoint
Data Sources
- Logon Session
- Application Log
- User Account
Created: 2024-11-14