View modified files for an entropy-based backup anomaly
When NetBackup detects an entropy-based backup anomaly, you can use the option to see which files changed within a specified time window around the anomalous backup. You can use this list to quickly spot unusual file changes, focus on suspicious paths or file names, and download it for analysis using your security tools.
Note:
The option is available only for entropy-based anomalies on Standard or MS-Windows policies. It is not available for other workload types. The option is also unavailable if the backup image has expired.
To use the option, the user must have the permission for .
To view modified files
- On the left, select Detection and reporting > Anomaly detection > Backup anomalies.
- Locate the entropy-based anomaly you want to investigate. Click the Actions menu and select View modified files.
- In the View modified files window, select a time frame to filter the results. All time frames are relative to the date of the anomalous backup:
Past 24 hours - Files that changed in the 24 hours leading up to the anomalous backup.
Past 48 hours - Files that changed in the 48 hours leading up to the anomalous backup.
Past 7 days - Files that changed in the 7 days leading up to the anomalous backup.
Since previous backup image - Files that changed since the backup image that preceded the anomalous backup. The filter label shows the date and time of that previous backup. This option is disabled if no previous backup image exists.
- Review the list of files. The following information is displayed for each entry:
File name - the name of the file that changed.
Path - the full directory path of the file.
Last modified - the date and time the file was last modified.
- To search for a specific file, enter the file name in the search field.
- To download all entries for the selected time frame, select Download CSV. The CSV file contains all results in the current view and can be imported into a SIEM or SOAR tool for further analysis.
Note:
If no files are detected within the selected time frame, the panel shows the message, No data to display. For custom time frame queries beyond the available filter options, NetBackup APIs are available.