Archive Engine HA Configuration
Starting with LogRhythm SIEM 7.25.0, the Archive Engine can be configured to operate correctly within a High Availability (HA) deployment. The following additional steps are required after installation or upgrade to ensure Archive Engine configuration data is stored on a shared, replicated volume and is available during failover.
Prerequisites
-
Archive Engine must be installed and enabled - see setup guidance: https://docs.logrhythm.com/lrsiem/docs/configure-the-archive-engine-service
-
HA must already be configured and operational.
-
Identify a shared DataKeeper replicated volume with sufficient free space for Archive Engine configuration and archive storage.
-
For Gen5 and newer appliances, the replicated volume is typically D:.
-
For Gen4 and earlier appliances, the replicated volume may be S: or another shared drive depending on the deployment.
-
-
If you need to determine which volumes are replicated, open the DataKeeper GUI and review the configured mirrored volumes.
1. Repoint HA Registry Configuration
After deploying LogRhythm SIEM 7.25.0 or higher:
-
New installations: Run through standard install setup HA_Install.ps1.
-
Existing deployments upgraded to 7.25.0: Run PostUpgrade.ps1.
These actions update the required HA registry entries for Archive Engine on the Active (Primary) node automatically. However, there is an additional setup step required for the Standby (Passive) server.
2. Configure the Standby Node
After completing the installation or upgrade procedures, log on to the standby HA node and run the following PowerShell command (can be done in a one lie execution).
Note: For Gen5 and newer appliances, leave the volume set to
$Vol="D". For Gen4 and earlier appliances, replace D with the appropriate replicated volume (for example,$Vol="S").
PowerShell Block;
$Vol="D";$HAPath="${Vol}:\LogRhythmHA\LRArchiveEngine\";if(Get-Service "LRArchiveEngine" -EA SilentlyContinue){$RegKey=if(Test-Path "HKLM:\Software\LogRhythm\LRArchiveEngine"){"HKLM:\Software\LogRhythm\LRArchiveEngine"}else{"HKLM:\Software\Wow6432Node\LogRhythm\LRArchiveEngine"};$Current=Get-ItemProperty $RegKey|Select CONFIGPATH,STATEPATH;$Current|ft -AutoSize;if($Current.CONFIGPATH -eq $HAPath){Write-Host "Already configured for HA - No action required" -f Green}else{$Confirm=Read-Host "Update to $HAPath ? (y/n)";if($Confirm -eq 'y'){@("CONFIGPATH","STATEPATH")|%{Set-ItemProperty -Path $RegKey -Name $_ -Value $HAPath};if((Get-ItemProperty $RegKey).DATAPATH){Set-ItemProperty -Path $RegKey -Name DATAPATH -Value $HAPath};Write-Host "Updated successfully" -f Green;(Get-ItemProperty $RegKey|Select CONFIGPATH,STATEPATH)|ft -AutoSize}}}else{Write-Host "LRArchiveEngine service not installed - skipping" -f Yellow};Push-Location C:\LK\Bin;$output=& "C:\LK\Perl\bin\perl.exe" "C:\LK\Bin\lcdstatus" -q;Pop-Location;$status=if(($output|Select -Skip 1 -First 1)-match "$env:COMPUTERNAME\s*$"){"ACTIVE HA Server"}else{"STANDBY HA Server"};Write-Host "You are on the: $status" -f Cyan
The script validates the current Archive Engine registry configuration and, if the paths are not already configured for HA, prompts you to update them automatically. It also displays whether the server is currently the Active or Standby HA node. In an HA deployment, both nodes should have the Archive Engine State and Config paths configured on a shared, replicated volume.
When prompted, enter Y to update the Archive Engine registry paths to the shared HA location.
The script:
-
Verifies that the Archive Engine service is installed.
-
Detects the correct Archive Engine registry location.
-
Updates the CONFIGPATH and STATEPATH values to the shared HA volume.
-
Displays the current HA node status (Active or Standby).
-
A subsequent re-run (once updated) should confirm updated location in green advising no further action required.
3. Configure Archive Storage Locations
After updating the registry settings, modify the following Archive Engine properties to use a shared, replicated volume:
|
Property |
Recommendation |
|---|---|
|
ActiveArchivePath |
Configure to a path on a shared replicated volume. |
|
InactiveArchivePath |
Configure to a path on a shared replicated volume. |
Example (Gen5+):
-
ActiveArchivePath = D:\LogRhythmArchives\Active\AIE
-
InactiveArchivePath = D:\LogRhythmArchives\Inactive\AIE
Using a replicated volume ensures archive data remains available following an HA failover event.
Verify Configuration
-
Confirm the registry paths were updated successfully.
-
Verify the Archive Engine service starts normally.
-
Confirm ActiveArchivePath and InactiveArchivePath point to replicated storage.
-
During next planned HA switchover, verify Archive Engine continues to archive AIE events successfully on the new active node.