> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment.md).

# Configure the Live Backup Environment

Live Backup enables you to mirror your production server to a backup server, and in disaster recovery scenarios to easily convert your backup server to be the production server.

When using Cortex XSOAR with Elasticsearch, Live Backup is not available. To back up or restore the contents of your Elasticsearch database, follow the instructions for [Disaster Recovery for Elasticsearch](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/elasticsearch/disaster-recovery-for-elasticsearch.md). Alternatively, you can also implement a full [high availability solution](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/high-availability/high-availability-overview.md).

{% hint style="warning" %}

### Caution

* Before you start, ensure that you save the disaster recovery configurations before you copy all files.
* If the main server has a custom certificate with password, you need to create a one-time-configuration (OTC) file (see [Step 8](#UUID-0ededbe5-14fc-2a8d-874b-3ebe2ad0d1e5_N1746601440519)).
* These instructions do NOT apply to multi-tenant deployments. Instead, follow the [Configure Live Backup](/cortex-xsoar-6-multi-tenant-guides/6.14/configure-multi-tenant/configure-the-multi-tenant-deployment/configure-live-backup.md) instructions in the multi-tenant guide.
  {% endhint %}

1. On the production server, enable live backup.
   1. Go to Settings → About → Troubleshooting → **Server Configuration**.
   2. Verify that the **External Host Name** is correct.
   3. Click **Add Server Configuration**.
   4. Add the following key and value.

      | Key                 | Value      |
      | ------------------- | ---------- |
      | **`ui.livebackup`** | **`true`** |
   5. Go to Advanced → **Backups** and in the **Live Backup** field, select **ON**.
   6. Add the following backup server parameters.

      | Parameters                             | Value                                                             |
      | -------------------------------------- | ----------------------------------------------------------------- |
      | `Hostname/IP Address`                  | Backup server IP address or Host name (without https\:// prefix). |
      | `Port`                                 | Default is 443.                                                   |
      | `Trust server certificate (unsecured)` | ON: certificates are not checked. OFF: certificates are checked.  |
      | `Use proxy`                            | Select whether to use a proxy.                                    |
2. On the backup machine (with a different hostname or IP address), install Cortex XSOAR.
   1. **`sudo ./demistoserver-xxxx.sh -- -dr -do-not-start-server`**
   2. Verify that the backup server is accessible from the production server through port 443 (or any other port configured as a listening port). Ensure that there are no firewalls that might drop communication.
3. On the production server, stop the Cortex XSOAR server:

   **`sudo service demisto stop`**
4. On the production server, create a tarball file of the necessary files and folders on the production server and copy it to the backup server.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>This process may take several hours, depending on your server specs and the amount of data that needs to be copied.</p></div>

   1. Ensure that all files and folders located in **`/var/lib/demisto`** have **`demisto:demisto`** ownership:

      **`chown -R demisto:demisto /var/lib/demisto`**
   2. Create the tarball file:

      **`tar --ignore-failed-read -pczf demistoBackup.tgz /var/lib/demisto/data /var/lib/demisto/artifacts /var/lib/demisto/attachments /var/lib/demisto/images /var/lib/demisto/systemTools /var/lib/demisto/d2_server.key /usr/local/demisto/cert* /usr/local/demisto/demisto.lic`**

      Sometimes the **`demisto.lic`** file is located in **`/var/lib/demisto/demisto.lic`** rather than **`/usr/local/demisto/demisto.lic`**. If so, change the directory in the command.

      If you have not set up a D2 server, you can remove **`/var/lib/demisto/d2_server.key`**.
   3. Verify the integrity of the tar file:

      **`md5sum demistoBackup.tgz`**
   4. Print the contents of the tar file to a text file:

      **`tar -tvf demistoBackup.tgz > demistoBackup.txt`**

      Do not delete the text file.
   5. Transfer the tarball file (**`demistoBackup.tgz`**) to the backup server, using your preferred tool such as scp:

      **`# scp demistoBackup.tgz root@<yourBackupServerIPortHostname>:/root`**
5. On the backup server, check the MD5 Checksum and compare it to the original file to verify the tar file is 100% valid:

   **`md5sum demistoBackup.tgz`**

   The MD5 sum is displayed. Compare this value against the MD5 sum saved in demistoBackup.txt in Step 4.
6. On the backup server, extract the backup tarball file (original file permissions and ownership are preserved):

   **`sudo tar -C / -xzpvf demistoBackup.tgz`**
7. Ensure all the copied files and folders have **`demisto:demisto`** ownership.
8. If the main server has a custom certificate with password, you need to add the key password to the one-time-configuration (OTC) file located in `/var/lib/demisto/otc.conf.json`. After the file is saved and the Cortex XSOAR server is restarted, the OTC file is automatically deleted. Add the following content to the OTC file: **`{"keypass":"certpassword"}`**. The `otc.conf.json` must have permissions for **`demisto:demisto`**.
9. Start the backup server:

   **`sudo service demisto start`**
10. Start the production server:

    **`sudo service demisto start`**

    If the procedure is successful, **Live Backup** is **ON**.

    If the server is active, Cortex XSOAR appears as usual when you connect. You can [Transition an Active Server to Standby Mode](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/transition-an-active-server-to-standby-mode.md) or [Transition a Standby Server to Active Mode](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/transition-a-standby-server-to-active-mode.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/onboarding-in-cortex-xsoar/disaster-recovery-and-live-backup/configure-the-live-backup-environment.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
