Home  ›  Glossary  ›  Backup Catalog

What is a backup catalog?

A backup catalog is the database a backup application keeps about its backups. It records what each restore point holds, when it was made, where it is stored and when it expires.

Every restore starts with a lookup in it. That makes it one of the most important and least noticed parts of a backup system.

The card index of a library

Imagine a library where every book is still on the shelves but the catalog has burned. Nothing is lost, yet finding one title means walking every aisle. A backup repository without its catalog is in the same state.

Someone asks for "the finance share as it was last Tuesday". The catalog turns that request into a list of exact files and locations on the backup target. That lookup is what makes point-in-time recovery quick. The same records tell the backup software which old restore points it can safely delete.

What the catalog keeps track of

  • Every restore point for every protected system, with its date.
  • A file index, so single files and emails can be searched for.
  • Where each piece of data lives: which disk, bucket, folder or tape.
  • Which backups depend on which, such as daily changes that rely on a weekly full.
  • Expiry dates for each restore point.
  • Which key or password protects each encrypted backup set.

Recovering when the catalog is gone

Ransomware that encrypts the backup server often takes the catalog with it. The team then reinstalls the software and scans every repository to rebuild the records. For large repositories that can take hours or days before the first real restore begins.

Worse cases exist. If encryption passwords lived only in the lost catalog, the backups may never decrypt.

The catalog can also list restore points whose data has been quietly damaged, a typical sign of backup tampering. Only an actual restore, the job of restore testing, shows which is true. A well-protected catalog looks like this:

  • The backup application's own configuration is backed up to a separate, locked location.
  • Backup metadata is written next to the data, so a fresh install can import it.
  • Encryption passwords are kept outside the backup server.
  • Importing backups into a clean install has been tried at least once.

ARTESCA and backup catalog

The catalog belongs to the backup application. ARTESCA holds the data it points to, as objects in S3 buckets. When the application writes its metadata into a locked bucket, S3 Object Lock applies to that metadata just as it does to the backups. In compliance mode, no user can delete it before its retain-until date.

ARTESCA audit logs can be forwarded to Splunk, Graylog, Elasticsearch or syslog. That gives a record of bucket access that does not depend on the backup server. ARTESCA does not rebuild a lost catalog, and it cannot recover passwords held only by the backup application. Both gaps fall to the wider data backup plan.