Networker

Re: [Networker] Antivirus exclusions or settings?

2012-10-19 08:47:48
Subject: Re: [Networker] Antivirus exclusions or settings?
From: Michael Leone <Michael.Leone AT PHA.PHILA DOT GOV>
To: NETWORKER AT LISTSERV.TEMPLE DOT EDU
Date: Fri, 19 Oct 2012 08:46:35 -0400
> In most cases you do the following:
> Any real-time scanning you disable on any and all EXE's that pertain
> to backups apps, and Db engines

Did that.

> You also exclude any directory that pertains to the backup app and 
> Db directory

Did that.

> Some AV programs can scan running processes, well you want to 
> exclude those too.

Did that.

> Outside of that, what are you experiencing that your current 
> exclusions are not helping? 

Slow speed. So much so, that  my weekend jobs are not finishing.

Specific example: I have an AFTD storage node. We do a full backup Friday 
night (2.4TB+), which then clones to LTO-4 tape (which is in a fiber 
attached library). Usually finishes completely in 28 hours or so. It gets 
done Sun morning, maybe a little after noon on Sunday.

Last weekend, we had hardware problems with the library. So I had to 
interrupt the job after it had saved about 700G to disk, but not yet to 
tape. 
So I restarted the job, which now was set to only backup 1.7TB and then 
clone. This was Sat morning, 10AM. (I didn't restart the same group; I 
made a new client entry, of only the specific folders that didn't finish, 
and ran that as a cloning job)

I interrupted the cloning on Mon afternoon, because it had not yet 
finished.

So a job that was significantly smaller (about 75% of the original job), 
took more than twice as long (over 50 hours), and still didn't finish.

I ended up having to manually clone the savesets, which went faster than 
when the running job cloned them, oddly. And more oddly, not every client 
experiences this same level of slowness, but every client has the same 
version of Kaspersky, which the same configuration (applied as a policy to 
all servers).

> Can you use a file watch tool to see what is getting accessed and by> 
what app? e.g. sysinternals has tools for this.

Kaspersky recommends their Enterprise version, which has an option - like 
Symantec - to not scan files opened for backup. Mind you, my server has 
file scanning completely turned off. The only scanning is on the clients 
and storage nodes.