Backup
NetCrunch automatically creates data backups each day. What a backup contains, whether it is encrypted, and what it can be restored onto all depend on the same thing: the credentials inside it.
NetCrunch Backup
Settings NetCrunch System Automatic Backup
Sometimes we need to save configuration files without saving collected monitoring data (performance trends and event log data).
backup-encryption
Encryption
Whether a backup file is protected depends on Advanced Data Security, not on whether the backup carries credentials.
Most backups include credentials, including the automatic daily one and Quick Backup. Leaving them out is something you choose, not the default.
With Advanced Data Security enabled, a backup carrying credentials is encrypted with AES-256 against your master password, and that password is what is needed to restore it. See NetCrunch Security Features.
With Advanced Data Security disabled — which is how NetCrunch ships — the backup file carries no password protection at all, even when it contains the credentials. The credential store travels inside it sealed with a fixed key that is identical in every NetCrunch installation, which is exactly what lets such a backup be restored on another machine without anyone typing anything.
Treat a credential-bearing backup taken without Advanced Data Security as if it were plaintext. It is portable precisely because nothing secret is protecting it. Keep it where you would keep the credential database itself, and do not hand it to anyone you would not hand the passwords to.
A backup created without the credentials carries no password protection either — but in that case there is nothing in it to lock.
Moving Data to Another Machine
You can save the backup file to a selected folder to move it to another machine. This backup will contain all configurations, including program registry settings and the monitoring credentials database.
That holds while the master key is under its default protection. If a master password has been set, the credentials in the backup can only be opened with that password.
Restoring on another machine without it still succeeds, but comes back without credentials — nodes, views, monitoring configuration and history are all intact, and only the stored secrets have to be re-entered. See NetCrunch Security Features.
Quick Backup
Quick Backup saves the Atlas configuration without the bulk data — it omits performance trends, the event log and device configurations, which are what make a full backup large. That is the whole of what "quick" means.
A Quick Backup still contains your monitoring credentials. It is not a redacted backup, and it is not automatically safe to hand to anyone.
What it leaves out is data, not secrets. It includes maps, credentials, program data, user profiles, and notes and tasks.
Sending a Backup for Diagnostics
If you are sending a backup to AdRem, exclude the credentials explicitly. Use the backup window and untick the passwords option rather than relying on Quick Backup to have done it for you.
A backup created without credentials carries no password protection either, which is what makes it something you can send. Untick events and trends at the same time and the file stays small.
A backup that does include credentials, taken from an installation with a master password set, cannot be read by anyone without that password — including AdRem. Sending one achieves nothing.