Intelligent protection of computing snapshots
A data management system (DMS) may support intelligent snapshot protection techniques. For example, the DMS may backup a computing system and facilitate that capture and storage of snapshots of the computing system. The DMS may identify a deletion event associated with one or more of the snapshots, the deletion event being associated with the one or more snapshots being deleted at a first time. The DMS may determine that deletion event is anomalous and retain the one or more snapshots beyond the first time. For example, the DMS may determine that one or more parameters associated with the deletion event are indicative of the deletion event being anomalous. In response, the DMS may retain the one or more snapshots for a retention period beyond the first time.
1 . A method, comprising:
receiving a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:
under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and
under the first retention policy, the one or more snapshots of the computing system would be nonexpired within the duration;
changing from the first retention policy to the second retention policy based at least in part on receiving the request; and
outputting, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.
2 . The method of claim 1 , further comprising:
verifying, based at least in part on outputting the indication that the one or more snapshots for the computing system are being retained, whether the expiration of the one or more snapshots was non-anomalous based at least in part on a multiple-party verification procedure; and
deleting, in response to verifying the expiration of the one or more snapshots was non-anomalous, the one or more snapshots.
3 . The method of claim 1 , further comprising:
identifying, based at least in part on changing the first retention policy to the second retention policy, a deletion event associated with the one or more snapshots of the computing system as a result of the one or more snapshots being expired under the second retention policy.
4 . The method of claim 3 , further comprising:
retaining, despite the deletion event occurring for the one or more snapshots, the one or more snapshots based at least in part on the one or more snapshots expiring within the duration after changing the first retention policy to the second retention policy.
5 . The method of claim 3 , further comprising:
determining, based at least in part on identifying the deletion event associated with the one or more snapshots of the computing system, that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous.
6 . The method of claim 5 , wherein determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous comprises:
determining that the one or more snapshots were generated within a threshold duration after the request to change the first retention policy to the second retention policy.
7 . The method of claim 5 , wherein determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous comprises:
determining that a quantity of the one or more snapshots satisfies a threshold quantity.
8 . The method of claim 5 , wherein a determination that the deletion event is anomalous is based at least in part on a capacity of a storage entity used to store the one or more snapshots.
9 . The method of claim 5 , further comprising:
retaining, in response to determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous, the one or more snapshots for a second duration.
10 . The method of claim 1 , further comprising:
storing the one or more retained snapshots in a second storage entity that is different than a first storage entity used to store the one or more snapshots, the second storage entity being associated with a greater access latency than the first storage entity; and
deleting the one or more retained snapshots from the first storage entity.
11 . The method of claim 1 , further comprising:
generating a data structure accessible by a user of the computing system that includes respective indications of the one or more retained snapshots.
12 . A data management system, comprising:
one or more processors; and
one or more memories storing instructions executable, individually or collectively, by the one or more processors to cause the data management system to:
receive a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:
under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and
under the first retention policy, the one or more snapshots of the plurality of snapshots of the computing system would be nonexpired within the duration;
change, from the first retention policy to the second retention policy based at least in part on receiving the request; and
output, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.
13 . The data management system of claim 12 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:
identify, based at least in part on changing the first retention policy to the second retention policy, a deletion event associated with the one or more snapshots of the computing system as a result of the one or more snapshots being expired under the second retention policy.
14 . The data management system of claim 13 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:
retain, despite the deletion event occurring for the one or more snapshots, the one or more snapshots based at least in part on the one or more snapshots expiring within the duration after changing the first retention policy to the second retention policy.
15 . The data management system of claim 13 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:
determine, based at least in part on identifying the deletion event associated with the one or more snapshots of the computing system, that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous.
16 . The data management system of claim 12 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:
store the one or more retained snapshots in a second storage entity that is different than a first storage entity used to store the one or more snapshots, the second storage entity being associated with a greater access latency than the first storage entity; and
delete the one or more retained snapshots from the first storage entity.
17 . A non-transitory, computer-readable medium storing code that comprises instructions executable, individually or collectively, by one or more processors of a data management system to cause the data management system to:
receive a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:
under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and
under the first retention policy, the one or more snapshots of the plurality of snapshots of the computing system would be nonexpired within the duration;
change, from the first retention policy to the second retention policy based at least in part on receiving the request; and
output, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.