Is it possible to configure only ARP snapshot to be deleted within 30 days?
Applies to
- OTNAP 9.11.1 or later
- Autonomous Ransomware Protection (ARP)
Answer
Partially, yes, because the ARP snapshot retention period is adjusted according to the
Attack Probability
status.- If the
Attack Probability
isnone
, the ARP snapshot is deleted after a maximum of 5 days (default).- The parameter can be modified using the
vserver option arw.snap.max.retain.interval.days
. - The parameter range is
1
to365
.
- The parameter can be modified using the
- If the
Attack Probability
islow
, the ARP snapshot retention period is adjusted accordingly when theAttack Probability
changes tonone
ormoderate
. - If the
Attack Probability
ismoderate
, the ARP snapshot is kept until marking it as afalse positive
.
Additional Information
- For more details about ARP snapshots, please refer to the "ARP Snapshots" section of the document Understanding ARP snapshot protection and attack detection.
- Please refer to Modify options for automatic Snapshot copies regarding
vserver option
.