Upgrading ESA
This section describes steps to upgrade ESAs.
To ensure compatibility and leverage new features, security fixes, and enhancements, it is necessary to upgrade the ESA to the latest version. This section outlines the required steps for upgrading from a previous version, applicable to both on-premise and cloud platforms.
Before you begin
Before beginning the upgrade, be sure to adhere to the following guidelines.
Freeze Policy and Ruleset Changes
Before upgrading the ESA, ensure all policy and ruleset changes are frozen.
No changes to the policies and rulesets should be made until the completion of the ESA upgrade.
Freeze Configurations in ESA
Prior to upgrading the ESA, freeze all configurations within the ESA. Ensure no configuration changes are made to any components in any of the ESAs until the upgrade is complete.
This section elaborates on the upgrade and configuration process for ESAs as per the Deployment with Default Audit logging flow to ESA Architecture diagram.
For more information about upgrading ESA, refer to Upgrading ESA to v10.
Upgrade Steps
On-Premise: Perform a full OS backup of all ESAs at both sites.
Cloud Premises: Take snapshots of each instance to ensure a restore point is available should any issues arise during the upgrade process.
For on-premise, refer to Working with OS Full Backup and Restore.
For AWS, refer to Backing up and Restoring Data on AWS.
For GCP, refer to Backing up and Restoring Data on GCP.
For Azure, refer to Backing up and Restoring VMs on Azure.
Disable the TAC replication job from Primary ESA P1.
Follow these steps to disable the TAC replication scheduled task:
- On the Primary ESA P1 Web UI, navigate to System > Task Scheduler.
- Click on the TAC replication scheduled task.
- Click Edit.
- Uncheck the Enable checkbox to disable the task.
- Click Save to save the changes.
- Click Apply to apply the changes.
Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA.
For more information about the prerequisites, refer to Prerequisites.
Upgrade ESAs S3, S4, and S5 at the Disaster Recovery (DR) site in parallel.
For more information on upgrading ESA, refer to:
Validate DR Site ESAs post upgrade.
Conduct a thorough validation of the upgraded ESAs at the DR site to confirm operational integrity and successful upgrade.
Perform the following validations in all the ESAs.
Log in to ESA Web UI.
Check for correctness of the version under About.
Navigate to Key Management > Key Stores in ESA Web UI and ensure that External Keystore configurations are intact.
Navigate to Settings > Users and check that External Groups settings are intact.
Navigate to Audit Store > Cluster Management. Check if ESAs S3, S4, and S5 are visible under Nodes tab, and the Cluster Status is GREEN.
Upgrade ESAs P1, S1 and S2 at the Primary site in parallel.
For more information on upgrading ESA, refer to:
Validate Primary Site ESAs post upgrade.
Conduct a thorough validation of the upgraded ESAs at the primary site to confirm operational integrity and successful upgrade.
Perform the following validations in all the ESAs:
Log in to ESA Web UI.
Navigate to Key Management > Key Stores in ESA Web UI and ensure that External Keystore configurations are intact.
Navigate to Settings > Users and check that External Groups settings are intact.
Navigate to Audit Store > Cluster Management. Check if ESA P1, S1, and S2 are visible under Nodes tab, and the Cluster Status is GREEN.
Enable Scheduler tasks in Primary ESA P1.
Enable the TAC replication scheduler task in Primary ESA P1. For replicating scheduler tasks, refer to Scheduler Tasks.
Migrate Audit logs from DR site ESAs to Primary site ESAs.
When the traffic from protectors is redirected to the DR site ESAs, audit logs are generated in these ESAs. These audit logs must be migrated to Primary site ESAs.
Before proceeding with executing the steps, take a note of the following:
Take a note of the time in hours/days that the protectors were pointed to DR site ESAs.
Under Audit Store > Cluster Management, on the Indices tab, make note of the indices that were created during the time frame in the preceding step.
Take a note of the ILM exported indexes that are created under the directory /opt/protegrity/insight/archive in each of the ESAs in DR site for that time frame.
To migrate Audit logs from DR site ESAs to Primary site ESAs, perform the following steps:
Log in to the web UI of ESA S3 in the DR site.
Perform ILM Export of all the indexes noted at step 2.
For more information about performing ILM Export, refer to Exporting logs.
Log in to OS console of ESA S3. Navigate to the directory /opt/protegrity/insight/archive.
Copy all the exported index files generated by ILM Export operation at step 2. Transfer these index files to ESA S2 in primary site under directory /opt/protegrity/insight/archive.
Additionally, log in to all the ESAs containing ILM exported index files noted at step 3 above and copy them to ESA S2 under directory /opt/protegrity/insight/archive.
Finally, perform ILM Import of all the index files copied from ESAs in DR site as per step 4 and step 5.
For more information related to ILM Import, refer to Importing logs.
Additional Considerations
Documentation: Maintain detailed records of the upgrade procedure for future reference.
Troubleshooting: Have contingency plans in place to address potential issues arising during the upgrade. For more information on troubleshooting, refer to Troubleshooting.
Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at
support@protegrity.com.
By following these structured steps, the upgrade and configuration of ESAs will be executed effectively, ensuring minimal downtime, and maintaining system integrity.
Feedback
Was this page helpful?