> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/back-up-the-database.md).

# Back up the Database

In Cortex XSOAR, you can perform both automated and manual backups, which store the entire database of incidents, playbooks, scripts, and user defined configurations. Cortex XSOAR stores daily, weekly, and monthly backup files.

{% hint style="info" %}

### Note

Any Cortex XSOAR service that uses the Elasticsearch database no longer runs automatic backups. To back up the contents of your Elasticsearch database, follow the instructions for [Disaster Recovery for Elasticsearch](/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/onboarding-in-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch.md).
{% endhint %}

You can define whether you want Cortex XSOAR to create automatic backups, and the location to store the backups. The database backup files are located in **`/var/lib/demisto/backup`**.

If you do not want to automatically backup your data, manual backups are recommended before doing server operations and maintenance work. When you want to migrate your whole database to another server, set up backups for additional Cortex XSOAR folders listed in step 3, using your standard backup tools, scheduled for off-peak hours.

1. Configure automated database backups.
   1. Select Settings → ADVANCED → **Backups**.
   2. Check that Automated Backups are enabled.
   3. **Backups Directory** - option to change where backups are stored.
   4. **Backup Time** - option to change the scheduled time for daily backups.
   5. Define the maximum number of daily, weekly, and monthly backups to store.
2. If you do not automatically back up your server, create a manual backup (before server operations or maintenance work).
   1. Stop the service by running the following command.

      **`sudo service demisto stop`**
   2. Create the backup file by running the following.

      **`cd /var/lib/demisto/data`**

      **`` tar -czf archive.tar.gz `find . -type f -name "demisto*db"` ``**

      Only demisto\*db files are stored (same as automated backup). The default directory for the database is **`/var/lib/demisto/data`**.

      The backup of the database directory should not be stored under **`/var/lib/demisto`**.
3. Back up additional directories.

   The following directories must be backed up manually, when you want to migrate your whole database to another server:

   * **`/var/lib/demisto/artifacts`**
   * **`/var/lib/demisto/attachments`**
   * **`/var/lib/demisto/images`**
   * **`/var/lib/demisto/d2_server.key`**
   * **`/var/lib/demisto/tools`**
   * **`/var/lib/demisto/versionControlRepo`**
   * **`/usr/local/demisto`**
   * **`/etc/demisto.conf`**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/onboard-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/back-up-the-database.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
