1 00:00:00,090 --> 00:00:02,190 ATR2500x-USB Microphone & Logitech BRIO: Have you ever thought about how many 2 00:00:02,190 --> 00:00:04,800 copies there are of your production data? 3 00:00:05,310 --> 00:00:09,419 There's the primary copies, snapshots copied to another array. 4 00:00:09,780 --> 00:00:12,660 Cloud snapshot stored in object storage. 5 00:00:13,080 --> 00:00:19,770 A copy each for dev and test other copies for analytics and of course, dozens to 6 00:00:19,770 --> 00:00:23,040 hundreds of copies for backup and Dr. 7 00:00:23,372 --> 00:00:27,872 Ever thought about who has access to all those copies, how long they're going 8 00:00:27,872 --> 00:00:32,132 to stay around and what they're costing the company while they hang around? 9 00:00:32,552 --> 00:00:33,212 No. 10 00:00:33,842 --> 00:00:35,132 Well, your welcome. 11 00:00:35,552 --> 00:00:38,372 You've just entered the world of copy data management. 12 00:00:38,762 --> 00:00:43,892 It's perhaps the most boring and the most important thing you can do to 13 00:00:43,892 --> 00:00:45,842 protect your company's information. 14 00:00:46,292 --> 00:00:48,392 And save money at the same time. 15 00:00:48,992 --> 00:00:50,002 Hi, I'm W. 16 00:00:50,002 --> 00:00:52,142 Curtis Preston aKA Mister backup. 17 00:00:52,472 --> 00:00:55,742 And each week on this podcast, we dive deep on one topic 18 00:00:55,742 --> 00:00:57,632 somehow related to backup Dr. 19 00:00:57,632 --> 00:00:58,442 And ransomware. 20 00:00:58,802 --> 00:01:03,362 We turn unappreciated, backup admins and to cyber recovery heroes. 21 00:01:03,572 --> 00:01:05,642 This is the backup wrap up. 22 00:01:19,438 --> 00:01:21,407 W. Curtis Preston: Hi, and welcome to the backup wrap up. 23 00:01:21,827 --> 00:01:22,577 I'm your host, W. 24 00:01:22,577 --> 00:01:27,107 Curtis Preston, I have with me my LinkedIn algorithm commiserater 25 00:01:27,132 --> 00:01:29,562 Prasanna Malaiyandi, how's it going? 26 00:01:29,562 --> 00:01:30,072 Prasanna. 27 00:01:30,582 --> 00:01:35,412 Prasanna Malaiyandi: I'm good, Curtis, and I am sorry that your LinkedIn 28 00:01:35,412 --> 00:01:39,192 stuff did not go as well as you were hoping it would go, but I think it's 29 00:01:39,192 --> 00:01:44,052 because they've probably caught up with you and realized how you use 30 00:01:44,052 --> 00:01:46,482 things and are like, okay, Curtis, Mr. 31 00:01:46,752 --> 00:01:49,932 Backup, we're going to change the algorithm just for him. 32 00:01:51,312 --> 00:01:51,552 W. Curtis Preston: Yeah. 33 00:01:51,552 --> 00:01:52,572 I don't, I don't think so. 34 00:01:52,572 --> 00:01:57,792 I think, you know, it's the, you know, when, when things go wrong, we're 35 00:01:57,792 --> 00:02:01,092 taught, what did you last change? 36 00:02:01,812 --> 00:02:06,072 And when I was taught, like when I had, we had these consultants 37 00:02:06,072 --> 00:02:07,542 that taught us how to use LinkedIn. 38 00:02:08,082 --> 00:02:12,612 One of the things they said was, don't post within 24 hours. 39 00:02:12,612 --> 00:02:12,882 Right. 40 00:02:12,882 --> 00:02:13,872 Don't, don't bang. 41 00:02:13,872 --> 00:02:17,652 You know that, that wait at least 24 hours before you do your big post. 42 00:02:18,402 --> 00:02:20,532 I didn't wait at least 24 hours. 43 00:02:20,592 --> 00:02:27,132 I tried something different yesterday where I posted to a group, um, with 44 00:02:27,132 --> 00:02:32,082 the link and, and just to see what kind of in attention I got there. 45 00:02:32,232 --> 00:02:36,372 And then today I posted to, you know, the greater LinkedIn. 46 00:02:36,747 --> 00:02:40,887 And, um, it was not 24 hours, it was more like 18. 47 00:02:41,367 --> 00:02:44,877 And so I think that in the end was my, my boo booo. 48 00:02:45,087 --> 00:02:47,037 So I won't make that boo booo again. 49 00:02:48,027 --> 00:02:52,767 Um, and uh, but yeah, I, yeah, so I think there are reasons. 50 00:02:52,767 --> 00:02:55,527 I don't think they just changed the algorithm 51 00:02:55,737 --> 00:02:57,372 Prasanna Malaiyandi: I don't know, maybe it's just Yep. 52 00:02:57,462 --> 00:02:58,902 Curtis, disable him. 53 00:02:58,902 --> 00:02:59,322 Done. 54 00:03:01,587 --> 00:03:04,137 W. Curtis Preston: yeah, I was having too much success on LinkedIn. 55 00:03:05,097 --> 00:03:05,457 All right. 56 00:03:05,457 --> 00:03:08,097 Well let's get onto the news of the week. 57 00:03:12,564 --> 00:03:17,664 First story of this week is a follow on from a story from a week or so ago, 58 00:03:17,664 --> 00:03:21,984 and that is what we originally referred to as the one password slash Okta hack 59 00:03:22,224 --> 00:03:24,204 really turned out to be an Okta hack. 60 00:03:24,204 --> 00:03:25,704 You want to talk about it Prasanna. 61 00:03:26,019 --> 00:03:29,859 Prasanna Malaiyandi: Yeah, so this is the one that we've been following along. 62 00:03:30,219 --> 00:03:33,639 Um, Okta had someone breach their environment, which then 63 00:03:33,639 --> 00:03:35,349 let them get into one password. 64 00:03:35,679 --> 00:03:39,759 Um, turns out that Okta recently finished their investigation and 65 00:03:39,764 --> 00:03:41,019 they published their findings. 66 00:03:41,619 --> 00:03:45,009 The findings were that one of their employees. 67 00:03:45,759 --> 00:03:51,849 Had a corporate device, they were using it to access a service account at Okta. 68 00:03:51,969 --> 00:03:52,239 Right. 69 00:03:52,239 --> 00:03:52,779 Typical. 70 00:03:52,779 --> 00:03:54,249 That's what you would do, right? 71 00:03:54,249 --> 00:03:58,809 They needed access to it and then they used their Chrome browser and 72 00:03:58,809 --> 00:04:03,849 they logged into their personal email account using the Chrome browser, and 73 00:04:03,854 --> 00:04:08,619 then when they went to go access using that service account, they said, save 74 00:04:08,624 --> 00:04:13,569 password, and the password for the service account then got stored in. 75 00:04:13,664 --> 00:04:18,224 The Chrome browser's password manager associated with their personal email 76 00:04:18,229 --> 00:04:22,134 account, and then supposedly somehow the employees, either personal 77 00:04:22,154 --> 00:04:26,984 device or their Gmail account was hacked, and that's how the bad actors 78 00:04:26,984 --> 00:04:28,454 got access to the service account. 79 00:04:30,024 --> 00:04:30,414 W. Curtis Preston: Yeah. 80 00:04:30,414 --> 00:04:33,084 So much to unpack here, right? 81 00:04:33,474 --> 00:04:38,274 Um, first, you know, just to understand, you know, we've talked about the Chrome 82 00:04:38,274 --> 00:04:43,464 and password manager before, and I, you know, we've put it in the category 83 00:04:43,469 --> 00:04:48,924 of it's better than nothing maybe, um, because of this problem, right? 84 00:04:48,924 --> 00:04:50,964 So it's better than nothing in that. 85 00:04:51,164 --> 00:04:54,284 It would allow you to have a unique password for every 86 00:04:54,464 --> 00:04:56,594 site, which that is good. 87 00:04:57,074 --> 00:05:01,214 But the problem that I have with the Chrome Password Manager is that 88 00:05:01,214 --> 00:05:05,444 it stores the data in such a way that you can pull it out, right? 89 00:05:05,444 --> 00:05:10,334 When you install one password or um, you know, Dashlane or any of 90 00:05:10,334 --> 00:05:12,734 these other guys, they will pull. 91 00:05:13,519 --> 00:05:18,079 Uh, they can pull your password stored in your browser out and then put them 92 00:05:18,079 --> 00:05:21,889 into your new password manager, which sounds really nice and convenient. 93 00:05:21,919 --> 00:05:26,539 What it should tell you is that there is an API to pull out the plain text data. 94 00:05:26,909 --> 00:05:30,029 All you have to do is ask the browser apparently. 95 00:05:30,029 --> 00:05:34,559 There was another article that was written in our Technica that basically said, no, 96 00:05:34,559 --> 00:05:38,009 Okta Senior Management, not an errand employee, caused you to get hacked. 97 00:05:38,009 --> 00:05:39,119 Do you wanna talk about that? 98 00:05:39,774 --> 00:05:42,239 Prasanna Malaiyandi: Yeah, and the big thing here is. 99 00:05:43,064 --> 00:05:47,834 ARS Technica article talks about the fact that there should have been IT 100 00:05:47,954 --> 00:05:52,634 policies in place to prevent these sort of things, and they covered the two 101 00:05:52,634 --> 00:05:53,984 that I remember off the top of my head. 102 00:05:53,984 --> 00:06:00,524 One is that for a service account, you shouldn't just allow anyone who has a 103 00:06:00,529 --> 00:06:01,904 credentials to be able to access it. 104 00:06:01,904 --> 00:06:06,284 You want to be able to limit the ips that can access it or do other things like 105 00:06:06,284 --> 00:06:10,514 that to make sure that you're restricting access, especially a service account is. 106 00:06:10,609 --> 00:06:11,659 Pretty powerful. 107 00:06:11,659 --> 00:06:15,949 And usually you don't have MFA associated with it because it's used 108 00:06:16,009 --> 00:06:20,299 in cases of running automated scripts or automated access, and so you 109 00:06:20,299 --> 00:06:22,219 can't really do MFA in those cases. 110 00:06:22,879 --> 00:06:26,599 So it makes sense to have the service account, but at the same time, you should 111 00:06:26,599 --> 00:06:29,989 restrict who has access and their ability and where it can be accessed from. 112 00:06:31,159 --> 00:06:36,979 The other part that they also mentioned in the article is that Okta, their 113 00:06:36,984 --> 00:06:39,999 IT policy should not allow personal. 114 00:06:40,664 --> 00:06:45,854 Accounts to be logged into from like a web browser to avoid the same issue. 115 00:06:46,454 --> 00:06:48,014 And there are multiple ways you could do this. 116 00:06:48,014 --> 00:06:51,734 You could either have a web proxy, you can, using Google 117 00:06:51,734 --> 00:06:54,704 Workspaces, you can actually restrict what domains are allowed. 118 00:06:55,394 --> 00:06:58,364 And so there are multiple tools that they could have done, but they 119 00:06:58,369 --> 00:07:01,904 did not have a policy in place, and that's what led to this issue. 120 00:07:03,194 --> 00:07:06,404 W. Curtis Preston: Yeah, I'd say it's gotta start with the policy, right? 121 00:07:06,434 --> 00:07:11,594 Don't log into your personal accounts from your computer, um, and then, 122 00:07:11,594 --> 00:07:15,344 and then, you know, do what you can to use technology to, to stop that. 123 00:07:16,204 --> 00:07:20,704 I also wonder if, if there's a way through, through technology, 124 00:07:21,724 --> 00:07:25,924 if we could go and blow away any stored passwords in any browsers. 125 00:07:26,914 --> 00:07:28,174 I wonder if that's possible 126 00:07:28,864 --> 00:07:31,894 Prasanna Malaiyandi: I'm sure with the device management software, there's 127 00:07:32,104 --> 00:07:34,024 W. Curtis Preston: Yeah, the di device management software. 128 00:07:34,024 --> 00:07:34,264 Yeah. 129 00:07:34,594 --> 00:07:34,894 Yeah. 130 00:07:35,104 --> 00:07:35,494 Okay. 131 00:07:36,934 --> 00:07:37,384 All right. 132 00:07:37,384 --> 00:07:39,724 Well let's talk about some good news. 133 00:07:39,814 --> 00:07:43,144 Um, and you know, I first wanna just put out a disclaimer. 134 00:07:43,204 --> 00:07:48,214 We don't purposefully go looking for Druva News because you and I used to work there. 135 00:07:48,754 --> 00:07:51,844 We just Google the same stuff that anybody else does, and it just so 136 00:07:51,844 --> 00:07:53,314 happened that in a couple of weeks, Dr. 137 00:07:53,314 --> 00:07:53,674 Made. 138 00:07:54,009 --> 00:07:58,839 A couple of, uh, big stories, and I think this one is probably my 139 00:07:58,839 --> 00:08:03,099 favorite story coming out of DVA in a while, and that is that they now 140 00:08:03,104 --> 00:08:08,019 support natively Azure backup of VMs. 141 00:08:08,079 --> 00:08:13,119 And specifically, not only do they support basically the, the snapshot. 142 00:08:13,504 --> 00:08:18,484 Method, which is the supported way to back up VMs inside Azure. 143 00:08:19,624 --> 00:08:24,934 They are then able to export those, uh backups, de-dupe them, 144 00:08:24,939 --> 00:08:29,054 and store them in the Druva cloud, it's what they do with AWS VMs. 145 00:08:29,054 --> 00:08:30,224 You get the best of both worlds. 146 00:08:30,224 --> 00:08:33,824 You get that native backup and recovery, and you get the cost 147 00:08:33,824 --> 00:08:37,604 savings of, um, the deduplication. 148 00:08:37,914 --> 00:08:40,554 , Prasanna Malaiyandi: I think for some of our listeners who may not be familiar. 149 00:08:41,074 --> 00:08:45,094 Why is it important, that second part that you mentioned of how they work, 150 00:08:45,094 --> 00:08:49,684 that they're taking the data, the backups out of the customer account 151 00:08:49,684 --> 00:08:51,154 and moving it to the DVA account. 152 00:08:51,159 --> 00:08:53,494 Why is that so critical in your opinion? 153 00:08:53,539 --> 00:08:55,489 W. Curtis Preston: Yeah, I think that, yeah, thanks for asking. 154 00:08:55,489 --> 00:08:59,419 So I would say that it's because of, you know, we're, we're always talking 155 00:08:59,419 --> 00:09:03,319 about getting an air gap, getting something that, that mimics an air gap 156 00:09:03,754 --> 00:09:05,929 if, if, of all your backups are in your. 157 00:09:06,499 --> 00:09:11,749 Uh, AWS or your Azure or your GCP account, then that account gets hacked. 158 00:09:11,839 --> 00:09:13,879 They take your backups with them, right? 159 00:09:13,879 --> 00:09:18,049 There are way too many stories about this that, uh, you need to 160 00:09:18,054 --> 00:09:20,389 get as much separation as you can. 161 00:09:20,389 --> 00:09:23,389 One of the ways to do that is to put it into another account that you own. 162 00:09:23,719 --> 00:09:27,169 I think the best way to do it is to put it into an account that you don't own. 163 00:09:27,544 --> 00:09:28,054 Right. 164 00:09:28,204 --> 00:09:32,884 Uh, in this case, this is what Druva is providing for both AWS and Azure is that 165 00:09:32,884 --> 00:09:36,484 it's pulling the data out, de-duping it stored in there, and by de-duping it, 166 00:09:36,484 --> 00:09:37,984 that's where they get the cost reduction. 167 00:09:37,984 --> 00:09:43,564 They're saying that it results in an overall reduction of TCO of 40%, which 168 00:09:43,564 --> 00:09:46,024 is, uh, you know, a solid number. 169 00:09:46,764 --> 00:09:47,124 Right. 170 00:09:47,664 --> 00:09:52,434 Um, and there is a cost to pulling the data outta the account. 171 00:09:52,794 --> 00:09:53,214 Right. 172 00:09:53,214 --> 00:09:56,604 I know that was the first thing you asked me was what about the, the, 173 00:09:56,604 --> 00:09:58,794 uh, the Egress cost, right? 174 00:09:58,824 --> 00:09:59,184 Yeah. 175 00:09:59,694 --> 00:10:03,114 Uh, but that cost is clearly offset by. 176 00:10:03,429 --> 00:10:05,289 The deduplication features, right? 177 00:10:05,289 --> 00:10:07,599 So you get the, you get the best of both worlds. 178 00:10:07,719 --> 00:10:09,494 Um, and this is good news for. 179 00:10:10,989 --> 00:10:16,899 Druva, you know, they, they acquired Cloud Ranger like five years ago and 180 00:10:16,959 --> 00:10:19,839 I think five years minus one day ago. 181 00:10:19,839 --> 00:10:21,189 I said, okay, that's great. 182 00:10:21,189 --> 00:10:22,119 What about Azure? 183 00:10:22,644 --> 00:10:22,934 Prasanna Malaiyandi: Yeah. 184 00:10:24,009 --> 00:10:26,619 W. Curtis Preston: And uh, so I'm glad to see that they're finally supporting 185 00:10:26,619 --> 00:10:36,000 it and I'm assuming that GCP is next well that is the news of the week . Alright. 186 00:10:36,000 --> 00:10:40,920 On this episode of our continuing backup to basic series, which 187 00:10:40,950 --> 00:10:44,130 of course what we're doing is we're working our way through. 188 00:10:44,475 --> 00:10:45,945 Modern data protection. 189 00:10:45,945 --> 00:10:49,065 My latest book here, I'll show, hold it up for the camera for the 190 00:10:49,125 --> 00:10:52,605 27 of you that are watching in the, the video version of this. 191 00:10:53,385 --> 00:10:56,775 We have a, we have a nice following on the audio side, but you know, 192 00:10:56,780 --> 00:10:58,005 I, I just think nobody knows. 193 00:10:58,010 --> 00:10:59,685 You can also watch this on YouTube. 194 00:11:00,165 --> 00:11:03,225 If you go search on the backup wrap up on YouTube, you can, you 195 00:11:03,225 --> 00:11:04,965 can watch our lovely little mugs. 196 00:11:05,685 --> 00:11:08,625 Um, I put a lot of effort into that video version, 197 00:11:08,685 --> 00:11:09,495 Prasanna Malaiyandi: Oh, I know you do. 198 00:11:10,515 --> 00:11:12,315 W. Curtis Preston: you know, nobody, nobody watches it. 199 00:11:14,115 --> 00:11:18,195 Just someday maybe we will, we'll be discovered on YouTube and then, 200 00:11:18,860 --> 00:11:19,665 Prasanna Malaiyandi: We take off. 201 00:11:19,995 --> 00:11:22,005 W. Curtis Preston: our, our, it'll just take off. 202 00:11:22,005 --> 00:11:27,165 But anyway, you know, you might think, and I did not do this on purpose, 203 00:11:28,065 --> 00:11:35,175 but the YouTube copy might just be, it's just one of the many copies 204 00:11:35,175 --> 00:11:39,015 of this show that I need to manage. 205 00:11:40,155 --> 00:11:41,025 You see what I did there? 206 00:11:41,265 --> 00:11:42,390 Prasanna Malaiyandi: I like what you did there. 207 00:11:43,875 --> 00:11:47,535 W. Curtis Preston: So we're talking this week about this phrase that I 208 00:11:47,535 --> 00:11:52,320 think, I think at one point it was really big, and then like lately, I, I, 209 00:11:52,325 --> 00:11:56,265 I don't hear the phrase too much, but again, it's a backup to basic series. 210 00:11:56,265 --> 00:12:00,375 So I want our listeners to know what this phrase is when it comes 211 00:12:00,375 --> 00:12:02,265 up in conversation and, and to know. 212 00:12:03,240 --> 00:12:09,330 It's pros and cons, uh, and the ways in which it might manifest itself. 213 00:12:09,510 --> 00:12:14,580 And that is, of course, copy data management or C uh, dmm. 214 00:12:14,820 --> 00:12:18,390 CDMI never hear I hear any, I never hear anybody call it CDM, 215 00:12:18,545 --> 00:12:19,910 Prasanna Malaiyandi: I, I haven't really heard. 216 00:12:19,910 --> 00:12:20,300 Yeah. 217 00:12:20,405 --> 00:12:20,695 W. Curtis Preston: They 218 00:12:20,695 --> 00:12:23,700 always, they always seem to say copy data management, 219 00:12:24,020 --> 00:12:25,460 Prasanna Malaiyandi: Copy data management, copy data 220 00:12:25,460 --> 00:12:26,810 management, copy data management. 221 00:12:27,150 --> 00:12:27,630 W. Curtis Preston: copy data. 222 00:12:28,820 --> 00:12:30,020 Prasanna Malaiyandi: It rolls off the tongue, you know, 223 00:12:30,780 --> 00:12:31,440 W. Curtis Preston: of copy data. 224 00:12:31,890 --> 00:12:33,180 Does it roll off the tongue? 225 00:12:33,200 --> 00:12:33,351 Prasanna Malaiyandi: it does. 226 00:12:33,960 --> 00:12:39,690 W. Curtis Preston: Um, so what do, do you want to sort of give the basic 227 00:12:39,695 --> 00:12:42,090 concept behind copy data management? 228 00:12:42,135 --> 00:12:44,355 Prasanna Malaiyandi: Yeah, so copy data management is really. 229 00:12:45,225 --> 00:12:47,745 It literally is what it says, right? 230 00:12:47,745 --> 00:12:48,375 It is. 231 00:12:48,615 --> 00:12:52,605 How do you manage the copies of data in your environment? 232 00:12:53,325 --> 00:12:56,475 Uh, it, depending on what you want to think about backup 233 00:12:56,475 --> 00:12:57,885 is one copy of the data. 234 00:12:57,890 --> 00:13:03,255 I know we've talked about replication and snapshots and CDP and near CDP, right? 235 00:13:03,255 --> 00:13:04,905 Those all create copies. 236 00:13:05,235 --> 00:13:06,825 Your archive, if you go off. 237 00:13:07,255 --> 00:13:08,875 Do archiving, right? 238 00:13:08,875 --> 00:13:10,555 That's another copy of the data. 239 00:13:11,005 --> 00:13:15,895 And so copy data management is sort of how do you manage all these copies and 240 00:13:15,900 --> 00:13:20,425 the life cycle of those copies because it's not just, okay, where are the copies? 241 00:13:20,425 --> 00:13:21,805 How do I create those copies? 242 00:13:21,805 --> 00:13:22,435 But also I. 243 00:13:22,650 --> 00:13:24,510 How long do I keep the copy around? 244 00:13:24,510 --> 00:13:27,420 Because different copies in different places will be kept 245 00:13:27,420 --> 00:13:28,890 for different periods of time. 246 00:13:29,220 --> 00:13:33,660 Snapshots, maybe I'm only keeping for 14 days backups, so maybe I'm keeping for 90 247 00:13:33,660 --> 00:13:38,970 days long-term retention slash archiving, maybe I'm keeping those for like 10 years. 248 00:13:39,270 --> 00:13:43,770 So how do I manage the retention process for those copies? 249 00:13:43,900 --> 00:13:48,010 And then the last bit of copy data management is really around how can 250 00:13:48,010 --> 00:13:50,230 I now start to use those copies? 251 00:13:50,890 --> 00:13:54,220 Which I think is kind of what a lot of people have now started to think 252 00:13:54,220 --> 00:13:57,580 about is, okay, I have copy of the data sitting there and I wanna just 253 00:13:57,580 --> 00:14:00,880 leave it sitting there because it could be useful for other business 254 00:14:00,880 --> 00:14:03,160 purposes for me to drive insights from. 255 00:14:03,700 --> 00:14:08,740 So how do I now start to manage the lifecycle of using a copy, destroying a 256 00:14:08,740 --> 00:14:12,250 copy, and keeping that around if need be? 257 00:14:13,925 --> 00:14:19,835 W. Curtis Preston: I Would describe it as like perhaps a more holistic view. 258 00:14:20,240 --> 00:14:22,760 Of all of the copies that are out there. 259 00:14:23,030 --> 00:14:26,630 You know, in, in our world, we tend to worry primarily 260 00:14:26,630 --> 00:14:28,760 about one of the copies, right? 261 00:14:28,940 --> 00:14:30,230 Or maybe two of the copies, right? 262 00:14:30,230 --> 00:14:32,030 We want at least two copies, right? 263 00:14:32,030 --> 00:14:34,910 You know, we wanna, we want a backup copy, hopefully on-Prem, and 264 00:14:34,910 --> 00:14:36,350 we wanna backup up copy off-Prem. 265 00:14:36,355 --> 00:14:37,670 So that's kind of two copies. 266 00:14:38,900 --> 00:14:43,700 And then a lot of people primarily focus on the, on the, on the, 267 00:14:43,820 --> 00:14:47,660 on the primary copy, the, you know, the, the production copy. 268 00:14:48,170 --> 00:14:54,560 Um, the, and you talked about copies that might be kept for archival purposes. 269 00:14:54,740 --> 00:14:59,120 I think the one, the only one that I, that I, uh, thought that you left 270 00:14:59,120 --> 00:15:02,060 out was the, the development side of 271 00:15:02,255 --> 00:15:02,975 Prasanna Malaiyandi: Test and dev. 272 00:15:03,080 --> 00:15:04,880 W. Curtis Preston: because that is, yeah, yeah. 273 00:15:04,880 --> 00:15:10,040 That is another big area where if you are a, if you're the type 274 00:15:10,040 --> 00:15:15,110 of company that does any kind of development or any kind of testing. 275 00:15:15,785 --> 00:15:20,645 Where you're, you know, where you, you want to have this other copy of your data. 276 00:15:21,215 --> 00:15:26,915 What you often want is you want production data, right? 277 00:15:26,915 --> 00:15:32,585 You want, um, a, a copy of your production data to use for testing you. 278 00:15:32,615 --> 00:15:35,915 Well, I'm just saying if you want, I know, I know why you're 279 00:15:35,915 --> 00:15:38,465 wincing, but, but if you want to, 280 00:15:38,525 --> 00:15:40,020 Prasanna Malaiyandi: Before it goes out to prod. 281 00:15:40,220 --> 00:15:40,620 I agree. 282 00:15:40,770 --> 00:15:41,060 Yeah. 283 00:15:41,780 --> 00:15:42,140 W. Curtis Preston: Right. 284 00:15:42,140 --> 00:15:43,100 If you want to test it. 285 00:15:43,100 --> 00:15:43,280 Right. 286 00:15:43,280 --> 00:15:46,070 I understand the, the concern that you're, that you're talking about. 287 00:15:46,400 --> 00:15:50,360 Um, but, and we, and we can talk about that, what, you know, that that's one of 288 00:15:50,365 --> 00:15:57,650 the things that you deal with in a copy data management, uh, configuration, right. 289 00:15:57,920 --> 00:16:01,910 The, the, the closer that you can use sandboxed. 290 00:16:02,810 --> 00:16:03,830 Information. 291 00:16:03,950 --> 00:16:04,490 Right. 292 00:16:04,550 --> 00:16:10,550 Um, so with, so for example, with Salesforce, right, you can very 293 00:16:10,550 --> 00:16:14,180 easily create a sandbox environment of your production environment. 294 00:16:14,810 --> 00:16:21,500 And it's got all of your production data over in that other, um, world, uh, so 295 00:16:21,500 --> 00:16:27,710 that you can test whatever new thing that you want to do without, uh, destroying 296 00:16:27,710 --> 00:16:30,680 your, yeah, without impacting your 297 00:16:30,935 --> 00:16:33,140 Prasanna Malaiyandi: I, I, I go back to the story that I think 298 00:16:33,145 --> 00:16:38,750 you've told us before on the podcast about how you, what was it? 299 00:16:38,750 --> 00:16:42,920 You downloaded Salesforce, you exported the Salesforce records, 300 00:16:43,130 --> 00:16:47,300 you sort of screwed up the changes and the rearranging of the tables 301 00:16:47,300 --> 00:16:51,110 completely ruined all the records, and you luckily had a backup, right? 302 00:16:51,440 --> 00:16:52,250 And you were able to go 303 00:16:52,445 --> 00:16:52,805 W. Curtis Preston: Yeah. 304 00:16:52,805 --> 00:16:54,845 I, I, um. 305 00:16:55,265 --> 00:17:00,695 Yeah, so first off, Excel, whoever wrote Excel and made it way too easy 306 00:17:00,695 --> 00:17:08,165 to sort just one column, why would anyone in the history of people want to 307 00:17:08,170 --> 00:17:11,975 sort just one column in a spreadsheet? 308 00:17:12,155 --> 00:17:15,155 It's got to be the non-fat, right? 309 00:17:15,155 --> 00:17:18,725 It's gotta be the one out of a hundred use case I, for the life of me. 310 00:17:18,725 --> 00:17:19,265 Can't think of. 311 00:17:19,745 --> 00:17:21,755 Any use case where that would be the case. 312 00:17:22,025 --> 00:17:28,925 But, uh, I sorted the phone number column, you know, and, and, and 313 00:17:28,925 --> 00:17:30,365 only the phone number column. 314 00:17:30,755 --> 00:17:34,235 And so I put all the wrong phone numbers to all the wrong, uh, 315 00:17:34,295 --> 00:17:38,585 people and, and then uploaded it, not realizing what I had done. 316 00:17:38,585 --> 00:17:41,375 And then I realized that I had basically destroyed a. 317 00:17:42,275 --> 00:17:44,765 A 2 million record Salesforce database. 318 00:17:44,765 --> 00:17:47,645 And luckily, luckily I had a backup of that. 319 00:17:48,105 --> 00:17:49,575 Prasanna Malaiyandi: You are like, thank God for that. 320 00:17:50,935 --> 00:17:52,850 W. Curtis Preston: So, so, well, what's the problem with that? 321 00:17:52,850 --> 00:17:58,250 What's the problem with the status quo where we have all of the, 322 00:17:58,250 --> 00:18:03,140 um, all of these copies around what, what's, what's the big deal? 323 00:18:03,155 --> 00:18:04,235 Prasanna Malaiyandi: There are multiple problems. 324 00:18:04,505 --> 00:18:07,625 One is from a compliance governance perspective, you 325 00:18:07,625 --> 00:18:08,705 need to know where your data is. 326 00:18:08,705 --> 00:18:12,455 If this is production data, you need to know where those copies are, who has 327 00:18:12,460 --> 00:18:16,685 access to it, who's spinning them up, how long are they being kept around for all of 328 00:18:16,690 --> 00:18:20,690 these things, which become very difficult when you don't know who's creating 329 00:18:20,765 --> 00:18:22,085 copies and where the copies are going. 330 00:18:22,790 --> 00:18:25,130 So that's kind of one problem, just compliance aspect. 331 00:18:25,130 --> 00:18:32,210 The other thing is you also want control over the lifecycle of those copies, right? 332 00:18:32,215 --> 00:18:34,160 How easily can I spin up a copy? 333 00:18:34,160 --> 00:18:37,700 Because if it takes me three weeks to copy over data, I. 334 00:18:38,540 --> 00:18:41,360 I have another copy that I can now start to use for tests that's going to 335 00:18:41,360 --> 00:18:46,010 impact my how quickly I can do testing and find issues and all the rest. 336 00:18:46,015 --> 00:18:51,410 And so you want mechanisms that make it easy to create these copies. 337 00:18:52,010 --> 00:18:55,370 And also along with the compliance piece, making sure 338 00:18:55,370 --> 00:18:57,050 that you have proper retention. 339 00:18:57,055 --> 00:18:58,970 You don't want these copies living around forever either. 340 00:18:59,540 --> 00:19:01,100 Right, because this is a copy of your data. 341 00:19:01,100 --> 00:19:05,990 It could be exfiltrated if someone, if you get hit by ransomware or a 342 00:19:05,990 --> 00:19:07,730 attacker gets into your environment. 343 00:19:08,180 --> 00:19:11,030 You don't want them pulling out like copies of your production data because 344 00:19:11,030 --> 00:19:13,640 you didn't realize, hey, someone had squirreled away a copy over here. 345 00:19:15,635 --> 00:19:15,935 W. Curtis Preston: Yeah. 346 00:19:15,935 --> 00:19:19,085 And to go back to the earlier thing, you don't want 'em pulling out 347 00:19:19,085 --> 00:19:20,855 copies of your development data. 348 00:19:20,860 --> 00:19:23,315 If your development data is copy of your production data. 349 00:19:24,155 --> 00:19:27,875 One of the, one of the reasons why you winced when I said that, uh, 350 00:19:27,875 --> 00:19:31,175 of course one of the things that we talk about when we do pull. 351 00:19:31,345 --> 00:19:33,745 Production data and put it into the development is this 352 00:19:33,745 --> 00:19:35,335 idea of masking it, right? 353 00:19:35,665 --> 00:19:37,555 So that you have product Yeah. 354 00:19:37,555 --> 00:19:38,305 Sanitizing. 355 00:19:38,305 --> 00:19:38,575 Yeah. 356 00:19:38,935 --> 00:19:43,435 Uh, so that you have production like data, but not actual production data. 357 00:19:44,115 --> 00:19:47,650 Prasanna Malaiyandi: One other thing to add with copy data management is it's not 358 00:19:47,650 --> 00:19:52,180 like you take one copy once and you're done forever with copy data management, 359 00:19:52,185 --> 00:19:53,710 there's an ongoing lifecycle it. 360 00:19:54,250 --> 00:19:57,850 Developers are constantly building new features, needing to test, right? 361 00:19:57,850 --> 00:20:00,820 So it's not like you could take a copy of your production environment 362 00:20:00,820 --> 00:20:04,000 from a year ago and continue to use it because things change. 363 00:20:04,150 --> 00:20:07,480 And so you also need that ability to refresh these copies and make that 364 00:20:07,480 --> 00:20:10,030 as automated and as easy as possible. 365 00:20:11,980 --> 00:20:12,370 W. Curtis Preston: Yeah. 366 00:20:12,370 --> 00:20:13,000 Agreed. 367 00:20:13,090 --> 00:20:17,225 Um, the, the other thing I, I, I think you alluded to it in your. 368 00:20:18,040 --> 00:20:21,945 You know, when I, when I was, when I was asking you about the, the, the 369 00:20:21,950 --> 00:20:28,600 problems of the status quo, one of the things, at least when CDM vendors were. 370 00:20:29,830 --> 00:20:35,290 Describing this, this new wonderful world of CDM was the cost of 371 00:20:35,290 --> 00:20:37,060 all of those copies, right? 372 00:20:37,060 --> 00:20:40,510 Did every one of those copies, I mean, you know, you talked about you definitely, you 373 00:20:40,510 --> 00:20:42,250 want to, you wanna manage that process. 374 00:20:42,250 --> 00:20:46,750 You wanna make sure that, that you, you know where all the copies are. 375 00:20:46,755 --> 00:20:50,380 You want to make sure that people are, the, the right 376 00:20:50,380 --> 00:20:51,730 people are accessing copies. 377 00:20:51,735 --> 00:20:54,010 The wrong people are not accessing those copies. 378 00:20:54,430 --> 00:20:57,400 Maybe some of the copies are encrypted, maybe some of them are not. 379 00:20:57,760 --> 00:21:01,810 Um, maybe they have different performance, uh, 380 00:21:02,500 --> 00:21:03,250 aspects. 381 00:21:03,250 --> 00:21:04,660 Right, right. 382 00:21:04,750 --> 00:21:05,680 Uh, yeah. 383 00:21:05,710 --> 00:21:07,690 Performance characteristics, better word. 384 00:21:08,200 --> 00:21:13,480 And the, but the, the other thing is that if, if all of your copies 385 00:21:13,480 --> 00:21:17,950 are indeed on extra storage, right? 386 00:21:17,950 --> 00:21:22,240 Or, you know, if, if each copy is on, on its own storage, that is 387 00:21:22,240 --> 00:21:24,490 a very expensive process indeed. 388 00:21:24,600 --> 00:21:24,890 Prasanna Malaiyandi: Yeah. 389 00:21:25,450 --> 00:21:29,560 And I know we talked the other day about snapshots and clones along with that, and 390 00:21:29,560 --> 00:21:34,900 that's one way to sort of get your space optimization is by taking clones on the 391 00:21:34,905 --> 00:21:39,010 same storage array that you have, the production or a copy of the production, 392 00:21:39,370 --> 00:21:43,390 you can now quickly spin up those copies in a space efficient manner, right? 393 00:21:43,390 --> 00:21:47,500 Rather than requiring hundreds of copies that are each occupying 394 00:21:47,590 --> 00:21:49,090 the full amount of dataset space. 395 00:21:50,950 --> 00:21:54,220 W. Curtis Preston: Yeah, so, all right, so that's our problem. 396 00:21:54,220 --> 00:21:58,000 The problem is that we have way too many copies that we're paying 397 00:21:58,000 --> 00:22:01,930 for way too many copies, each of which is its own attack vector. 398 00:22:03,100 --> 00:22:07,030 And, and, and we still, we still want to protect all of that, right? 399 00:22:07,030 --> 00:22:09,490 We want to protect it from a backup and recovery and 400 00:22:09,490 --> 00:22:11,260 disaster recovery perspective. 401 00:22:11,885 --> 00:22:12,175 Prasanna Malaiyandi: Whoa. 402 00:22:12,250 --> 00:22:14,500 W. Curtis Preston: how does cd, what, what did I 403 00:22:14,595 --> 00:22:16,690 Prasanna Malaiyandi: Just that last one about we wanna protect it. 404 00:22:16,690 --> 00:22:17,365 I think it depends. 405 00:22:18,985 --> 00:22:19,645 You may not 406 00:22:19,690 --> 00:22:20,560 W. Curtis Preston: don't want to predict it. 407 00:22:20,755 --> 00:22:24,685 Prasanna Malaiyandi: well, the copies you may not care about your 408 00:22:24,880 --> 00:22:27,340 W. Curtis Preston: Well, I just, I just, I just meant the data. 409 00:22:27,370 --> 00:22:28,390 The data in general. 410 00:22:28,750 --> 00:22:28,870 Yeah. 411 00:22:28,875 --> 00:22:30,970 We don't necessarily want to protect each copy. 412 00:22:30,970 --> 00:22:32,590 I just meant the data in general. 413 00:22:33,190 --> 00:22:36,520 Um, you know, if we have nine copies of the different data, we 414 00:22:36,520 --> 00:22:37,630 only want to protect one of them. 415 00:22:37,630 --> 00:22:37,840 Right. 416 00:22:39,440 --> 00:22:39,660 Prasanna Malaiyandi: So, 417 00:22:39,700 --> 00:22:40,720 W. Curtis Preston: So we're on, we're on the same 418 00:22:40,980 --> 00:22:41,590 Prasanna Malaiyandi: okay, good. 419 00:22:42,130 --> 00:22:42,350 So. 420 00:22:44,590 --> 00:22:47,590 Yeah, so just trying to understand the environment and I think this is 421 00:22:47,590 --> 00:22:53,020 where it becomes difficult because differentPrasannaonas in your 422 00:22:53,020 --> 00:22:57,430 organization use different tools and have different requirements. 423 00:22:58,535 --> 00:22:58,955 W. Curtis Preston: Mm-Hmm 424 00:22:58,990 --> 00:23:01,390 Prasanna Malaiyandi: I look at, say your database admin. 425 00:23:02,125 --> 00:23:06,025 They're gonna wanna spin up a copy, copy off a production in order 426 00:23:06,025 --> 00:23:07,675 to be able to do testing, right? 427 00:23:07,675 --> 00:23:10,465 Or to give to the database team for them to do application 428 00:23:10,465 --> 00:23:11,785 development and all the rest of that. 429 00:23:11,875 --> 00:23:15,145 And so they're gonna wanna copy off of that using their own tools. 430 00:23:15,145 --> 00:23:18,295 So they might integrate with something that is more database 431 00:23:18,295 --> 00:23:22,225 friendly, like Delphix, which allows for spinning up test and dev copies 432 00:23:22,225 --> 00:23:24,025 off of Oracle and other databases. 433 00:23:24,745 --> 00:23:27,175 Then you have, uh. 434 00:23:27,805 --> 00:23:31,735 Folks who might wanna care about, okay, I need to be able to spin up 435 00:23:31,735 --> 00:23:33,895 a copy to do like my backup team. 436 00:23:34,255 --> 00:23:38,635 I wanna be able to spin up a copy to make sure that I can verify my backups. 437 00:23:39,820 --> 00:23:42,760 And make sure that I could restore my data in case I need to. 438 00:23:42,760 --> 00:23:44,170 So do backup verification. 439 00:23:44,920 --> 00:23:48,880 And so in order to do that, I need to spin up a copy off of my backup 440 00:23:48,880 --> 00:23:53,500 system in order to be able to access that copy, do my testing without 441 00:23:53,505 --> 00:23:55,120 impacting the original backup. 442 00:23:55,420 --> 00:23:56,050 'cause that's a key. 443 00:23:56,260 --> 00:23:58,900 You don't wanna change any of the original data, you just wanna 444 00:23:58,900 --> 00:24:00,130 copy of that data and manage it. 445 00:24:00,550 --> 00:24:02,020 And so there's a separate lifecycle for that. 446 00:24:03,295 --> 00:24:06,445 W. Curtis Preston: And I think that there are products like Veeam, and I 447 00:24:06,445 --> 00:24:08,365 know Rubrik has done this quite a bit. 448 00:24:08,365 --> 00:24:10,825 I believe, uh, Cohesity has done this quite a bit. 449 00:24:11,290 --> 00:24:13,285 I, I know Druva did this as well. 450 00:24:13,615 --> 00:24:18,385 Um, well, they, yeah, they specifically, Dr you know, since I 451 00:24:18,535 --> 00:24:20,365 worked there, but specifically Dr. 452 00:24:20,365 --> 00:24:21,505 For, for VMware. 453 00:24:21,895 --> 00:24:25,735 But, uh, uh, so that's, you know, you talked about Delphix. 454 00:24:25,795 --> 00:24:29,035 There are products that are specifically aiming at this. 455 00:24:29,590 --> 00:24:31,865 Backup side of of CDM. 456 00:24:31,975 --> 00:24:32,275 Prasanna Malaiyandi: Yep. 457 00:24:32,365 --> 00:24:37,655 And I think one of the biggest challenges you have is each Prasanna 458 00:24:37,675 --> 00:24:38,725 is gonna use a different tool. 459 00:24:38,725 --> 00:24:42,805 I know three, or like five, seven years ago, everyone was like, Hey, 460 00:24:42,805 --> 00:24:46,975 we'll just have one single tool that can cover the entire environment, 461 00:24:47,245 --> 00:24:49,105 that can manage copies everywhere. 462 00:24:49,525 --> 00:24:52,495 And I think that's just a difficult problem to solve. 463 00:24:53,410 --> 00:24:53,860 Right. 464 00:24:54,100 --> 00:24:58,600 Uh, because you're never gonna have that one tool that everyone likes because every 465 00:24:58,600 --> 00:25:02,770 Prasanna is going to want their own tools or gonna have their own custom workflows. 466 00:25:03,280 --> 00:25:07,595 And so it's hard to say there is a single ring to rule them all. 467 00:25:09,685 --> 00:25:14,455 W. Curtis Preston: Yeah, I, I think that's probably Actifio that, that 468 00:25:14,905 --> 00:25:16,825 that's what Actifio was going for. 469 00:25:16,885 --> 00:25:17,305 Right? 470 00:25:17,785 --> 00:25:22,045 Um, they eventually got acquired, I forgot by whom I. 471 00:25:22,570 --> 00:25:27,430 But, um, the, that, that was certainly what their goal was, right? 472 00:25:27,430 --> 00:25:30,370 Was to, was to provide a copy, a copy for everybody. 473 00:25:30,620 --> 00:25:32,270 It's like everything else in the IT world. 474 00:25:32,875 --> 00:25:36,350 If, if you do everything, you're not gonna be any good at anything, right? 475 00:25:37,580 --> 00:25:42,560 And so, and so, you're going to run into, you know, like the delphix of the 476 00:25:42,565 --> 00:25:44,420 world or the, the beams of the world. 477 00:25:44,420 --> 00:25:48,350 You're gonna run into somebody who's really good at that particular workflow. 478 00:25:49,295 --> 00:25:55,955 And so, um, so, so it sounds like what we're saying is there's, at least right 479 00:25:55,955 --> 00:26:02,045 now, we're not aware of any one tool that meets all of these copy data management, 480 00:26:02,465 --> 00:26:06,245 uh, needs for every type of, uh, workflow. 481 00:26:06,665 --> 00:26:07,590 Prasanna Malaiyandi: that I'm aware of. 482 00:26:07,590 --> 00:26:13,140 The only thing you could possibly do is have some sort of reporting tool 483 00:26:13,500 --> 00:26:17,250 that's at least able to discover where all the copies are and kind of 484 00:26:17,250 --> 00:26:18,780 stitch together a picture for you. 485 00:26:18,780 --> 00:26:22,860 But that may not give you sort of the orchestration you need across everything. 486 00:26:23,874 --> 00:26:26,454 W. Curtis Preston: We look at the world of copy data management, I, I 487 00:26:26,454 --> 00:26:28,764 see sort of, I think there's like. 488 00:26:29,184 --> 00:26:31,074 Three big things, right? 489 00:26:31,074 --> 00:26:34,794 So one is the discovery, where is everything? 490 00:26:35,034 --> 00:26:36,594 Where are all my copies? 491 00:26:37,014 --> 00:26:40,174 And then the second one is who has access to those copies? 492 00:26:40,534 --> 00:26:45,179 And then the third is, um, how long are those copies going to be around? 493 00:26:46,399 --> 00:26:51,679 Because for, and I'd say that's primarily for cost reasons, 494 00:26:51,679 --> 00:26:53,269 but it's also for risk reasons. 495 00:26:53,269 --> 00:26:53,479 Right? 496 00:26:53,479 --> 00:26:56,329 Because as long as something is sitting around, it's something that 497 00:26:56,329 --> 00:26:58,399 can be, uh, potentially attacked. 498 00:26:59,329 --> 00:27:01,429 Does, do you think that sums up the, the, 499 00:27:01,714 --> 00:27:02,299 Prasanna Malaiyandi: I, I. 500 00:27:02,334 --> 00:27:03,109 W. Curtis Preston: we're worried about? 501 00:27:04,699 --> 00:27:06,829 Prasanna Malaiyandi: I know you talked about cost, but I wanted 502 00:27:06,829 --> 00:27:08,449 to talk a little bit about that. 503 00:27:09,019 --> 00:27:11,089 But yes, I agree with the three things that you summed up 504 00:27:12,364 --> 00:27:12,694 W. Curtis Preston: Right. 505 00:27:12,694 --> 00:27:15,509 Well, the cost is sort of the reason we care about the, the, 506 00:27:15,664 --> 00:27:17,494 the three, the third thing, right? 507 00:27:17,494 --> 00:27:19,054 That, that, that time. 508 00:27:19,769 --> 00:27:19,989 Um, 509 00:27:20,179 --> 00:27:22,879 Prasanna Malaiyandi: Well, I wanna mention though, why copy data management, though 510 00:27:23,209 --> 00:27:29,629 sort of has gotten better now and why it was talked about a lot more versus before. 511 00:27:30,789 --> 00:27:31,079 W. Curtis Preston: okay. 512 00:27:31,984 --> 00:27:33,904 Prasanna Malaiyandi: One of the things, and also some of the 513 00:27:33,904 --> 00:27:35,074 downsides of copy data management. 514 00:27:35,079 --> 00:27:40,444 So one of the things is when you had sort of traditional disc spinning up 515 00:27:40,444 --> 00:27:44,734 a copy was even if you had snapshots and clones, you could do that. 516 00:27:44,739 --> 00:27:48,064 So you're not consuming extra space, but it would take a performance hit. 517 00:27:49,234 --> 00:27:54,754 And when you started to look at SSDs, now you can actually afford to spin up 518 00:27:54,754 --> 00:27:57,304 a copy and offer the same performance. 519 00:27:58,249 --> 00:28:01,519 To those other application use cases without necessarily fully 520 00:28:01,519 --> 00:28:03,709 impacting your production data source. 521 00:28:03,709 --> 00:28:06,139 That's what a lot of people are concerned about, which is why they would copy 522 00:28:06,139 --> 00:28:10,219 off the data to a secondary system and then spin up their test in Dev with 523 00:28:10,219 --> 00:28:13,219 SSDs and high performance Flash arrays. 524 00:28:13,399 --> 00:28:17,359 You no longer had to worry about that as much, and so you can now spin up copies. 525 00:28:17,359 --> 00:28:21,079 Like if you talk to our friend Howard at Vast Data, right? 526 00:28:21,079 --> 00:28:23,449 I'm sure VAs will say, yeah, just spin up as many copies as you 527 00:28:23,449 --> 00:28:24,679 want off of the vast production. 528 00:28:24,679 --> 00:28:25,159 You'll be fine. 529 00:28:26,614 --> 00:28:32,254 So that's one way that sort of production copies became a lot more. 530 00:28:32,824 --> 00:28:37,114 Affordable and also not as much concern from performance perspective. 531 00:28:37,774 --> 00:28:42,964 Now, the other thing I will mention is backup target systems have always been 532 00:28:43,384 --> 00:28:45,094 sort of like, Hey, we have all this data. 533 00:28:45,099 --> 00:28:46,354 How do we add more value? 534 00:28:46,354 --> 00:28:48,124 How do we allow people to use the data? 535 00:28:48,124 --> 00:28:51,529 And I know we talked about backup verification testing or restore 536 00:28:51,609 --> 00:28:55,174 verification testing, but people started then thinking about can we 537 00:28:55,174 --> 00:28:59,884 start to use backup systems for test and dev scenarios and other things like 538 00:28:59,914 --> 00:29:00,334 W. Curtis Preston: Mm-Hmm. 539 00:29:01,099 --> 00:29:06,079 Prasanna Malaiyandi: Now if you look at an all flash array system, which I don't 540 00:29:06,079 --> 00:29:11,569 think many purpose build backup appliances exist, which are purely all flash just 541 00:29:11,569 --> 00:29:16,459 because of cost reasons for those systems, they mix flash with a good amount of disc. 542 00:29:16,609 --> 00:29:22,189 And so yes, you might be able to spin up 1, 2, 3 copies off of that system, but 543 00:29:22,189 --> 00:29:25,759 at some point you're gonna run into a performance limitation much sooner than 544 00:29:25,759 --> 00:29:27,649 you would off of your primary system. 545 00:29:28,789 --> 00:29:30,559 The other thing also is. 546 00:29:31,009 --> 00:29:35,209 People don't typically associate backup systems with doing these test 547 00:29:35,214 --> 00:29:39,169 and dev copies because backup was built for a reason, and that's to 548 00:29:39,169 --> 00:29:42,889 provide you sort of that last line of defense against everything else blowing 549 00:29:42,934 --> 00:29:43,264 W. Curtis Preston: Right. 550 00:29:43,849 --> 00:29:47,479 Prasanna Malaiyandi: And so is that something from a risk perspective, 551 00:29:47,484 --> 00:29:51,919 as a backup admin, you really wanna give the keys to everyone 552 00:29:51,919 --> 00:29:55,999 who wants a test in dev copy to be running off of that backup system. 553 00:29:56,634 --> 00:29:59,184 Or really is your main focus of that backup system? 554 00:29:59,184 --> 00:30:00,534 Hey, I'm the last line of defense. 555 00:30:00,534 --> 00:30:04,614 My goal is to make sure I can restore data, meet my SLAs, protect 556 00:30:04,614 --> 00:30:07,824 data in the corporate environment, and test and dev really should be 557 00:30:07,824 --> 00:30:10,974 run by a different organization or go talk to the production admins. 558 00:30:12,024 --> 00:30:16,584 And so that's why I think copy dev or copy data management never really took off 559 00:30:16,584 --> 00:30:22,104 as much as people wanted to from backup systems as it has from production systems. 560 00:30:23,794 --> 00:30:29,134 W. Curtis Preston: Yeah, and the, and, and I think for other reasons, like 561 00:30:29,134 --> 00:30:31,119 we want to keep you, you talked about. 562 00:30:31,879 --> 00:30:37,669 Why not to use the backup system as a source for copies for test and dev. 563 00:30:38,179 --> 00:30:43,649 And I'm also saying why not to think of the backup as just another copy. 564 00:30:43,894 --> 00:30:52,319 Because when, when it's, when you know if we get that full CDM system, if backup 565 00:30:52,319 --> 00:30:58,109 is just another copy, my question is how connected is it to this primary system? 566 00:30:58,484 --> 00:31:06,194 That could go offline and, and does that in some way, uh, put my backup and Dr. 567 00:31:06,194 --> 00:31:07,424 Copy at risk. 568 00:31:07,689 --> 00:31:09,339 Prasanna Malaiyandi: And my business at risk, right? 569 00:31:09,344 --> 00:31:11,499 Because that is the purpose of the backup and Dr. 570 00:31:11,499 --> 00:31:12,069 Copies. 571 00:31:13,734 --> 00:31:14,274 W. Curtis Preston: Right. 572 00:31:14,364 --> 00:31:20,274 And so I, I think that there's still a good argument to be 573 00:31:20,274 --> 00:31:23,094 made for keeping backup and dr. 574 00:31:23,094 --> 00:31:30,024 Copies separate and then production and dev copies perhaps together, uh, provided 575 00:31:30,024 --> 00:31:35,934 off of the same storage because as, and as long as you do it in such a way 576 00:31:35,934 --> 00:31:37,554 that you're not impacting production. 577 00:31:37,674 --> 00:31:37,914 Prasanna Malaiyandi: Yeah. 578 00:31:38,709 --> 00:31:41,889 W. Curtis Preston: Um, if, if you're, and I, I think that with 579 00:31:41,889 --> 00:31:47,979 flash, that does solve, uh, that or that ameliorates that concern. 580 00:31:48,939 --> 00:31:53,349 Um, and then, you know, we haven't talked at all about cloud copies 581 00:31:53,939 --> 00:31:54,159 Prasanna Malaiyandi: Yes. 582 00:31:54,519 --> 00:31:58,479 W. Curtis Preston: because I think that's where the true, like it's 583 00:31:58,479 --> 00:32:03,669 so easy to just spin up another copy of something in the cloud. 584 00:32:04,344 --> 00:32:06,504 Then forget about it, right? 585 00:32:06,509 --> 00:32:10,704 It's so easy to make an S3 copy of something to make a, a copy 586 00:32:10,704 --> 00:32:14,454 of something in EBS to clone a VM from here over to there. 587 00:32:15,234 --> 00:32:20,994 Um, I think that when, when we, now, you know, early in this recording I 588 00:32:20,999 --> 00:32:23,189 talked about, I used the word holistic. 589 00:32:24,954 --> 00:32:28,764 You really have to bring, you know, when we say whole, the whole part 590 00:32:28,764 --> 00:32:32,304 of holistic, we've been talking primarily about the data center, but 591 00:32:32,309 --> 00:32:36,234 we really should be talking about those copies in the cloud because 592 00:32:36,294 --> 00:32:43,794 it is so easy to create both backup, archive development copies, et cetera. 593 00:32:44,664 --> 00:32:47,664 Entire instances, right? 594 00:32:47,664 --> 00:32:53,934 Entire, um, virtual data centers That then no longer get used. 595 00:32:54,189 --> 00:32:56,899 Prasanna Malaiyandi: Yeah, and that's a big thing from like a cost perspective 596 00:32:56,899 --> 00:33:01,399 because I'm sure there are companies out there which have a bunch of either. 597 00:33:01,999 --> 00:33:07,159 Snapshots or EC2 instances running that they aren't even able to keep track 598 00:33:07,164 --> 00:33:10,699 of because at some point you have so much infrastructure running, you don't 599 00:33:10,704 --> 00:33:12,079 know what is being used for what. 600 00:33:12,079 --> 00:33:16,369 And so that becomes a concern because that starts to eat 601 00:33:16,369 --> 00:33:18,109 because it's not cheap right? 602 00:33:18,739 --> 00:33:19,309 To run that. 603 00:33:19,309 --> 00:33:22,189 It's not your own data center, you're co, you're worrying about, but you're still 604 00:33:22,189 --> 00:33:27,499 paying AWS or Google or whoever your cloud provider is for those resources. 605 00:33:29,074 --> 00:33:29,554 W. Curtis Preston: Right. 606 00:33:29,609 --> 00:33:33,389 I think I'm agreeing with you that I don't think there is the one, 607 00:33:34,139 --> 00:33:36,239 the one tool to rule them all. 608 00:33:36,839 --> 00:33:41,369 Because there's a data center versus the cloud for no other reason other than that. 609 00:33:42,599 --> 00:33:48,209 But there could be a tool that could manage, that could do 610 00:33:48,209 --> 00:33:50,129 these, the three things, right? 611 00:33:50,459 --> 00:33:54,719 Uh, find all my copies, uh, find out who has access to them and find out 612 00:33:54,719 --> 00:33:55,949 how long they're gonna be around. 613 00:33:56,189 --> 00:34:01,139 And then also I think in the cloud there are ways to find out if a particular 614 00:34:01,139 --> 00:34:03,389 resource is actually still being used. 615 00:34:04,199 --> 00:34:05,054 Prasanna Malaiyandi: I am sure there is. 616 00:34:05,054 --> 00:34:05,264 Yeah. 617 00:34:06,614 --> 00:34:07,124 W. Curtis Preston: Yeah. 618 00:34:07,154 --> 00:34:10,964 And so if we can, if we can identify these resources that aren't being 619 00:34:10,964 --> 00:34:14,534 used and then get rid of them, and then I think that that's sort 620 00:34:14,539 --> 00:34:17,534 of that initial, uh, challenge. 621 00:34:17,564 --> 00:34:21,104 But then once you get that initial lay of the land, I think if you 622 00:34:21,104 --> 00:34:26,204 have a tool that can then be the one who creates the copy for you, 623 00:34:26,369 --> 00:34:26,659 Prasanna Malaiyandi: Yeah. 624 00:34:27,284 --> 00:34:27,584 W. Curtis Preston: right? 625 00:34:27,974 --> 00:34:30,614 Uh, if it can create the copy for you rather than just 626 00:34:30,614 --> 00:34:32,204 you as using native tools. 627 00:34:32,909 --> 00:34:38,639 Um, then I think that you could get that cost aspect and risk aspect, I 628 00:34:38,639 --> 00:34:40,289 think a little bit more in control. 629 00:34:40,904 --> 00:34:44,624 Prasanna Malaiyandi: and I think in the cloud also because of the ability to tag 630 00:34:44,624 --> 00:34:47,984 resources, you get a lot more flexibility. 631 00:34:47,984 --> 00:34:49,814 So you could say, Hey, I'm spinning up this test and 632 00:34:49,814 --> 00:34:51,254 dev copy for this department. 633 00:34:51,254 --> 00:34:56,984 You could tag it in your EC2 instance, and you could use that later to track 634 00:34:56,984 --> 00:34:58,634 and understand, okay, who's using what? 635 00:34:59,054 --> 00:35:02,174 So I think a cloud helps with a lot of the manageability aspects. 636 00:35:02,174 --> 00:35:03,464 You just have to use it in the right way. 637 00:35:05,879 --> 00:35:10,469 W. Curtis Preston: Yeah, I think tags are, I think tags are, um, you know, uh, 638 00:35:10,474 --> 00:35:16,289 an amazing tool that, uh, are really, they're, they're helpful tags, are 639 00:35:16,289 --> 00:35:17,969 very helpful for a number of things. 640 00:35:17,969 --> 00:35:19,739 This is copy data management is one of them. 641 00:35:19,979 --> 00:35:22,229 Another area where they're helpful is backup and recovery. 642 00:35:22,919 --> 00:35:27,329 Um, because you can apply rules to different tags, right? 643 00:35:27,329 --> 00:35:31,559 And you can say, we're gonna, we're gonna handle, um, our VMware cloud 644 00:35:31,619 --> 00:35:34,409 instances like this, and we're gonna handle our, you know, our 645 00:35:34,409 --> 00:35:36,749 EBS instances like this, et cetera. 646 00:35:36,749 --> 00:35:42,929 And you can just, you, you can attach rules and backup and DR policies 647 00:35:42,989 --> 00:35:45,899 to those rules, uh, based on tags. 648 00:35:45,929 --> 00:35:47,549 And you, you can even have. 649 00:35:48,009 --> 00:35:53,109 Um, you can say, Hey, if a resource gets created and it doesn't have 650 00:35:53,114 --> 00:35:55,839 a tag at all, this is what we do. 651 00:35:56,234 --> 00:35:56,924 Prasanna Malaiyandi: The default. 652 00:35:57,044 --> 00:35:58,569 W. Curtis Preston: One, one of which, yeah. 653 00:35:58,569 --> 00:36:00,159 The, the default policy. 654 00:36:00,159 --> 00:36:03,429 And, and, and part of that policy would be to go yell at somebody 655 00:36:03,429 --> 00:36:06,549 to say, Hey, why is there, why is there this resource without tags? 656 00:36:07,119 --> 00:36:13,149 Um, just to finish out, we, we talked a little bit about, uh, the reuse of data. 657 00:36:13,479 --> 00:36:16,449 Um, I think that. 658 00:36:17,384 --> 00:36:25,064 This, there are, you know, as long as I've been in backup, there's been 659 00:36:25,064 --> 00:36:28,604 a lot of talk, especially in the last, I'd say 10 or 15 years, there's 660 00:36:28,604 --> 00:36:32,744 been a lot of talk about trying to leverage backup for other purposes. 661 00:36:32,744 --> 00:36:34,124 You've touched on it already. 662 00:36:34,409 --> 00:36:40,754 Um, I, I think from a, you know, backup is different than archive. 663 00:36:41,024 --> 00:36:44,564 I do think that if you stored the data correctly, if you stored 664 00:36:44,564 --> 00:36:46,184 the data in such a way that. 665 00:36:46,589 --> 00:36:50,759 You had information available for both backup and archive instances, 666 00:36:50,759 --> 00:36:55,319 and you were able to meet both workloads with the same copy of data. 667 00:36:55,409 --> 00:36:56,879 I would be fine with that. 668 00:36:57,329 --> 00:36:59,514 I very rarely have found I. 669 00:37:00,344 --> 00:37:01,694 You know, backup software. 670 00:37:01,694 --> 00:37:07,364 I, I'd say about the only one that I've seen that does it, at least the best that 671 00:37:07,369 --> 00:37:10,094 I have seen would be Commvault, right? 672 00:37:10,094 --> 00:37:12,644 That they have a single copy and they have both backup and archive. 673 00:37:12,644 --> 00:37:15,734 Now, the concern that I've, that I've heard is that it does 674 00:37:15,739 --> 00:37:18,014 require a significant amount of additional infrastructure. 675 00:37:18,519 --> 00:37:26,114 Um, but I, I, I don't have a problem with that additional cut because that I see as. 676 00:37:26,654 --> 00:37:30,134 You're saving money by storing one copy and using it for 677 00:37:30,284 --> 00:37:30,674 Prasanna Malaiyandi: multiple 678 00:37:30,884 --> 00:37:33,044 W. Curtis Preston: I just don't want people, right. 679 00:37:33,104 --> 00:37:36,884 I, I just don't want people taking their backup and then holding it for 680 00:37:36,884 --> 00:37:38,444 10 years and calling that an archive. 681 00:37:38,474 --> 00:37:41,354 That is not an archive that we've, we've had episodes about that. 682 00:37:41,774 --> 00:37:44,714 Um, I will talk about that till I'm blew in the face. 683 00:37:45,404 --> 00:37:51,344 Um, and, and other, other things that we can use backup for is to. 684 00:37:52,004 --> 00:37:56,984 Basically look at the backup and leverage it from a ransomware perspective. 685 00:37:57,044 --> 00:38:00,464 We, we can look at and see if we can identify that the ransomware 686 00:38:00,464 --> 00:38:02,714 attack has been, has happened. 687 00:38:03,134 --> 00:38:06,344 Uh, we can see that if anything has been encrypted, we can see if anything 688 00:38:06,344 --> 00:38:08,324 has been infected in the backup. 689 00:38:08,329 --> 00:38:10,214 We can do that with the backup copy. 690 00:38:11,084 --> 00:38:13,904 Um, but I think I agree with you. 691 00:38:14,414 --> 00:38:19,574 Um, and, and potentially, and this is potentially, uh, if 692 00:38:19,574 --> 00:38:21,074 we have backup an archive. 693 00:38:21,464 --> 00:38:27,104 If we have that, potentially we could use backup for, uh, compliance 694 00:38:27,549 --> 00:38:27,769 Prasanna Malaiyandi: Yep. 695 00:38:28,664 --> 00:38:28,964 W. Curtis Preston: right? 696 00:38:28,994 --> 00:38:34,214 If, if we're able to easily query and, and, and this is a big if, right? 697 00:38:34,214 --> 00:38:39,464 Because in order to meet compliance needs, you need to be able to, 698 00:38:39,764 --> 00:38:43,604 the system has to act more like an archive system than a backup system. 699 00:38:44,024 --> 00:38:47,624 I need to be able to say, show me all the files that Curtis made, right? 700 00:38:47,624 --> 00:38:50,414 I need to say, show me all the emails with this word in them. 701 00:38:50,789 --> 00:38:52,739 Show me all the documents with this word in 702 00:38:52,979 --> 00:38:54,959 Prasanna Malaiyandi: which most backup systems don't focus on. 703 00:38:55,769 --> 00:38:56,429 W. Curtis Preston: which mode? 704 00:38:56,429 --> 00:38:57,389 Backup systems. 705 00:38:57,389 --> 00:38:57,659 Yeah. 706 00:38:57,929 --> 00:38:59,489 Almost none, basically. 707 00:38:59,999 --> 00:39:05,759 Um, there have been some advancements, uh, to, to, you know, to do some 708 00:39:05,759 --> 00:39:09,234 stuff, but it's just not there. 709 00:39:09,779 --> 00:39:10,259 Right. 710 00:39:10,289 --> 00:39:14,069 And, and even then, it's often very. 711 00:39:14,504 --> 00:39:15,704 Application centric. 712 00:39:15,704 --> 00:39:19,274 Like we can do it for 365, but we can't do it for other stuff. 713 00:39:19,274 --> 00:39:19,544 Right? 714 00:39:19,814 --> 00:39:25,064 So again, if, if you want to use backup for archive purposes, I'm sorry, for, 715 00:39:25,064 --> 00:39:31,214 for compliance purposes, then you, um, you just need to make sure that 716 00:39:31,214 --> 00:39:32,624 it's capable of meeting that workload. 717 00:39:33,269 --> 00:39:33,329 Prasanna Malaiyandi: Yeah. 718 00:39:35,594 --> 00:39:36,134 I agree. 719 00:39:37,784 --> 00:39:38,204 W. Curtis Preston: Okay. 720 00:39:39,794 --> 00:39:40,094 All right. 721 00:39:40,094 --> 00:39:42,734 Well, we have once again beat this topic to death. 722 00:39:42,984 --> 00:39:46,884 If you found this topic, uh, interesting and you wanna read more, you know, 723 00:39:46,914 --> 00:39:52,014 similar topics, uh, you can get my book, modern Data Protection Available 724 00:39:52,014 --> 00:39:56,784 wherever books are sold, including, you know, in Rivers in South America. 725 00:39:57,399 --> 00:40:01,074 Um, some people don't like to buy books there. 726 00:40:01,074 --> 00:40:01,614 That's fine. 727 00:40:01,644 --> 00:40:02,154 I don't care. 728 00:40:02,184 --> 00:40:03,444 I don't care where you buy my book. 729 00:40:06,174 --> 00:40:09,264 Uh, all right, well thank you very much, Prasanna for a great discussion. 730 00:40:09,609 --> 00:40:11,229 Prasanna Malaiyandi: As always, Curtis, it was a lot of fun. 731 00:40:13,269 --> 00:40:15,039 W. Curtis Preston: And thank you to our audience. 732 00:40:15,039 --> 00:40:16,509 We'd be nothing without you. 733 00:40:16,779 --> 00:40:19,059 And with that, that's a wrap.