How ARP Snapshot parameters behave based on the Attack Probability status?
Applies to
- ONTAP version 9.10.1 or later
- Autonomous Ransomware Protection (ARP)
- Modify options for automatic snapshots
Answer
- Beginning with ONTAP 9.11.1 multiple parameters can control the ARP snapshot existence.
ontap911::> options arw*arw.snap.create.interval.hours 4arw.snap.create.interval.hours.post.max.count 8arw.snap.max.count 6arw.snap.max.retain.interval.days 5arw.snap.new.extns.interval.hours 48arw.snap.normal.retain.interval.hours 48arw.snap.surge.interval.days 5- Above highlighted parameters behave dependent on attack probability.
- If the attack probability is
moderate, ARP snapshots will not be deleted based on these settings until the attack is resolved and the probability drops tonone - For a detailed explanation of the logic, please refer directly to Understanding ARP snapshot protection and attack detection
Additional Information
N/A
