After the NetApp Autonomous Ransomware Protection (ARP) response workflow processes an event, you can review the detected event and any files that were marked as threats in Command Center. After you review the event, you can restore backup data without including files that are marked as threats.
Review the detected event
NetApp ARP events that Commvault processes are displayed as partner signals in Threat Scan.
To review a NetApp ARP event:
-
From the Command Center navigation pane, go to Secure > Threat scan.
-
Select the affected resource.
-
Click the Partner signals tab.
-
Select the NetApp ONTAP ARP signal to view the event details.
Review files marked as threats
When the workflow validates suspect files against the Commvault index, matching files are marked as threats for the affected resource.
To review files that were marked as threats:
-
From the Command Center navigation pane, go to Secure > Threat scan.
-
Select the affected resource.
-
Click the Threats tab.
-
Review the files that were marked as threats.
Restore backup data
After suspect files are marked as threats in the Commvault index, you can restore backup data without including corrupted files or files that are marked as threats.
-
On the Threats tab, click the restore option to start the restore operation.
-
Restore the backup data without including corrupted files or files that are marked as threats.