Skip to main content
Matrix42 Self-Service Help Center

Shadowcopy

Overview

Shadowcopy creates shadow copies of files used by users on external storage devices, thin client storage, network shares or cloud storage. The copies are first saved on the client computer and then transferred to the defined shadow copy server. The administrator can then access the shadow copies from the Console.
The usage of Shadowcopy is dependent from the Secure Audit module:

  • To make it possible to activate Shadowcopy for a user/computer, enable auditing under Product settings | Audit | Secure Audit. For details, see: Activating Secure Audit
  • As soon as you configure Shadowcopy for a storage, the audit of the file accesses to this storage location is also configured automatically. For details, see: Configuring Shadowcopy
  • Once Shadowcopy is activated for a user/computer, the Secure Audit product is activated automatically, if it was not activated before. For details, see: Activating Shadowcopy for user/computer

Settings for shadow copies on special storage directories:

Shadowcopy from…

Necessary settings

Network shares

Enable the option Allow network shares control under:

  • Administration | Clients | Client settings
  • Computer management | Settings | Client settings

Thin client storage

Enable the option Allow thin client storage control under:

  • Administration | Clients | Client settings
  • Computer management | Settings | Client settings

Cloud

Define controlled cloud storage types under User management | Settings | Cloud storage.

Configuring and activating Shadowcopy

Managing Shadowcopy server

You can use an existing EgoSecure Server as a shadow copy server or install/create a separate shadow copy server. During the installation specify which server type to use. You can change the setting later in the AdminTool.

Changing existing server type

  • Open the AdminTool. By default, the application is located in the EgoSecure Server folder in the EgoSecure installation directory.
  • Under Server type, enable the Management+ShadowCopy radio button.

clipboard_e3dd90f9e0b93bf9e2b8074d63965a1f6.png

  • In the lower area, enable the Accept audit data and Accept shadowcopy data checkboxes.
  • Click Save and close the AdminTool.
  • You can now use the current EgoSecure Server installation as a shadowcopy server and configure Shadowcopy.
  • If you use multiple shadowcopy servers, you can set a preferred shadowcopy server for each client.

Setting up a preferred shadowcopy server

  • In Console, go to Installation | EgoSecure agents | Install/Update.
  • In the Install/Update area, select an Agent. To select multiple Agents, hold down Ctrl and click.
  • Select Favorite ShadowCopy Server | [server name] from the context menu.
  • The selection appears in the Favorite SC server column.

Configuring Shadowcopy

To use Shadowcopy, decide the following:

Finally: enable Shadowcopy for user and computer.

Applying global settings for shadow copies

  • Open the Console and go to Product settings | Audit | Secure Audit.
  • Select the locations from where shadow copies must be made.
  • If you enable a shadow copy, the audit of file accesses of this device type enables automatically.

clipboard_e6927a0b2b4c8f987dc4e9d5ccb690b0b.png

  • If needed, in the Operation filter column, select the operation for which no shadow copy must be created.
  • Click Save.
  • The selection is inherited to default users, default computers and all users/computers:

clipboard_e15558b65789737f4a18aaa129ae35f18.png

Shadowcopy filter

You can limit or exclude shadow copies of certain file types. To limit and exclude, specify how shadowcopy filters work (blacklist or whitelist) and assign the filters globally (using default policies) or individually (to user/computer). For details, see: Filters

Configuring file filter for shadow copies

  • Go to Product settings | Audit | Shadowcopy filter.
  • Enable the Activate shadowcopy filter check box.
  • Select how shadowcopy filters work:
    • White list: Only files that match the filter definitions are copied to the server.
    • Black list: Files that match the filter definitions are not copied to the server. All other files are copied.

clipboard_eb229eee9f926d436dfdd14af7eb9ea88.png

  • If necessary, create a new filter under Product settings | Filters | File type filters. Filters created there can be used for both Access Control and ShadowCopy.
  • Click Save.
  • You can now assign filters for shadow copy. For details, see: Activating shadowcopy for user/computer

clipboard_e9fdf11926d74ea8d01235caeeb5d509d.png

Adjusting storage settings for shadow copies on the Server

  • Go to Product settings | Audit | Shadowcopy.
  • To change the location of shadow copies on the server,
    • Click Browse in the Shadowcopy server settings area.
    • In the Simultaneous clients field, define from how many Agents shadowcopy uploads can be performed simultaneously.
    • In the Maximum net load field, specify the permitted maximum network load for shadowcopy uploads. E.g.: if network has a transmission rate of 100 Mbit/sec and we define the maximum network load as 30%, shadowcopy uploads can use only network transmission rate not higher than 30 Mbit/sec.
    • To automatically delete shadow copies from the server after a certain time, enable the Delete after... checkbox and enter the number of days after which the deletion occurs.
    • As soon as a shadow copy is older than x days, it is automatically deleted from the server.
  • 3.   To change the location of shadow copies,
    • Click Browse in the Shadowcopy client settings area.
    • Under How much disk space can be used for the Shadowcopy, define how many % or GB of the hard disk space/partition can be used for shadow copies on the Client.
    •  Select when to copy files to the Server:
      • ®  Immediately: The shadow copy is copied to the Server immediately after creation and can be opened/saved via the Console.
      • ®  After computer start: The shadow copy is copied to the Server after the client restart and can be downloaded via the Console.
      • ®  Scheduled: Shadow copies are copied to the Server once a day at the specified time and can be downloaded via the Console.
      • ®  By request: The shadow copy becomes available for downloading on the Server only if under User management/Computer management | Audit | File access tab an audit entry is right-clicked and Increase upload priority option is selected.
  • Specify an upload retry interval to repeat a sending of a file copy from Agent to Server one more time if a previous upload failed.
  • Click Save.
  • The settings are applied.

Activating shadowcopy for user/computer

  • Go to User management/Computer management | Audit.
  • Right-click a user/computer and select Activate/deactivate products | Shadow Copy.
  • Open the Settings tab in the lower area.
  • The user automatically inherits the Shadow Copy settings of a default user.
  • To define individual shadow copy settings for the user/computer and to deactivate shadow copy for certain storage locations, enable the Activate individual settings check box and disable the corresponding shadow copy check boxes.

clipboard_e95b900760caf083011c7bccafaee1b22.png

  • To apply a file type filter to shadow copies, enable the filter in the Shadowcopy filters tab. For details, see: Shadowcopy filter
  • Click Save.

Opening and saving shadow copies

You can open or save shadow copies in the following areas:

  • User management/Computer management | Audit | File access and Unencrypted
  • Reports | Audit | File access

clipboard_e5e66e28ee18933fdb836e73419f06288.png

Opening or saving shadow copy

  • In the SC column, click on  and select Open or Save as.

If in the shadow copy settings the By request option is selected, the following symbol is displayed in the SC column:

  • In the context menu, select Shadowcopy | Increase upload priority.
  • The appears the symbol  and the copy can now be downloaded.

 

  • Was this article helpful?