00:05
All right. Good morning, good afternoon, good evening, wherever you may be joining us in the world, or you might be watching this, in later format in a recording. Welcome to our Near-Zero RTO in Action webinar. We're gonna talk a lot today about what Pure Storage and Rubrik are doing together. Specifically, how we're able to take some of that information from Rubrik Security Cloud,
00:29
that threat intelligence information, and pull that in to what we're doing inside of Pure Fusion, with Pure Storage. So I'm My name is Scott Taylor. Should probably introduce that first. I'm our director for cyber resilience here at Pure Storage, and I have some very special
00:44
guest with me here today. From Rubrik, Mr. Ray Felix. Ray is the AVP of, it's a lot of things here, guys, Technical Product- Alliance and Competitive Research. So as you can imagine, the more things you have with your in your title, I think the more
00:58
important you are. I believe that's how that actually works. And then also, colleague of mine from Pure Storage, Mr. Roy Child, Principal Solution Architect for us. He's, he's the guy that actually makes a lot of this stuff happen, you know. People like me, sometimes we just talk.
01:13
Roy actually makes this stuff happen. Gentlemen, welcome to our webinar today. Thanks, Scott. Thank you, buddy. Appreciate it. All right. I think we're gonna jump in, like, right away, right?
01:25
Let's, let's go talk about some of this stuff and what are we doing. Let's see if I can make a presentation work. You know, I'm hoping that people are familiar with our cyber resilience stack, right? Combining that awesome Rubrik Security Cloud, and let's just say overall Rubrik solution, with the power of what we bring to the table with Pure, kind of across
01:43
our entire product line. But let's go a little bit deeper into this. And Ray, I'm gonna, I'm gonna turn it over to you, and I, I think this slide has some build-out. I'm just gonna go ahead and build it out if that's okay with you. Yeah, please.
01:52
Let me take us through, like, what does this all mean? What, what are we actually doing? What kind of value are we bringing to our customers? Thank you, buddy. So gang, back in September of 2024, we launched the Cyber Resilience Stack with the intent of helping customers to understand how
02:09
to create a layered defense against ransomware. And so we took the FlashArrays, the Rubrik Security Cloud with secure vault and our threat analytics, and the FlashBlade Archive, and we helped folks to configuration for each to give you the best chance at recovering from an attack. Now, if you recall that document, that- that's great.
02:34
If you don't, I'll give you the, the CliffsNotes version. On the FlashArrays, we recommended doing, SafeMode Snapshots as a first layer of defense. And, in the Rubrik Security Cloud, we're running the full enterprise edition suite with anomaly detection, with threat monitoring, with threat hunting, with turbo threat hunting, giving us the ability to quarantine anything that we find in your backup catalog that looks
03:01
suspicious, that has an indicator of compromise. And then, we archive that data out safely and securely for Rapid Restore to those FlashBlades, and we lock it down with, object lock, which is, space efficient and secure, or bucket-level immutability. So in January this year when we launched the Cyber Resilience Visibility integration to
03:26
layer on top of that Cyber Resilience Stack, what we're trying to do is give you the ability to recover good, clean data from anywhere in one of those three layers. What I'll do really quickly here is walk you through how this integration works at a high level. We start with a backup.
03:43
Rubrik refers to policies as SLA domains. So an SLA domain is really a backup policy that contains the frequency, the retention, the archive, the replication requirements for any number of workloads in your environment. In this case, we would protect VMware. That's what we built the integration for first and foremost.
04:05
So I'm gonna define that SLA domain, at my VMware workloads, and that SLA gonna go create all the recover points on my behalf. I don't have to schedule anything or load balance anything or worry about proxy servers or, space consumption on any particular repository. Rubrik does all of that for you automatically.
04:27
Once that data is ingested into the Rubrik secure vaults and, erasure coding is laid out, we'll do of the content itself, so we can look files inside of your, your, your VMware virtual machines and give you a lay of the land so you can perform object-level recoveries. That's when the threat analytics piece starts.
04:49
So folks might be familiar with the, the Mandiant Feed, which has 1.3 million and counting indicators of compromise listed. And what we're essentially doing with we're mounting these recover points inside of the Rubrik platform and performing a scan against those one point three million, IoCs. We're looking for YARA rules, for file hashes, for su- suspect file paths.
05:17
And if we see anything that feels suspect, anomalous change rates, encryption on the hypervisor, we quarantine the data in our catalog, and the goal for that is to keep you from reinfecting your environment during recovery. This is where the integration comes into play, folks. So, Pure1 workflow automation allows us to string together these products to allow
05:42
them to work together seamlessly to pass the results from that threat analysis back to Pure. So we're actually correlating the volumes where the data came from and the snapshots that could possibly contain those indicators of compromise.And so now as a Pure administrator, if I log into Pure Fusion and I'm looking at my fleet, I can see my
06:09
volumes, I can see things that Rubrik has tagged as suspicious, as quarantined, and more importantly, I can see the cleanliness of my backup catalog, of my snapshot catalog, so that when I need to perform recovery, I have a variety of sources to do that from. I can pull big, massive 200, 300 TiB snapshots of data back cleanly directly from the Pure array with a near-zero RTO.
06:39
I can perform a z- a surgical recovery with, Rubrik Security Cloud, power up any number of systems with a live mount, do, overwrite in place, object level recovery, or I can pull that data from my longterm Flash archive where that data's been sitting nice and secure, protected by Object Lock. That's my speech, gang. I'll take a pause there.
07:03
Scott, back to you, buddy. Well, before I pause the slide side, and we get into a little bit more of the discussion, Roy, is there anything comment on, you know, around some of the details of the integration? Yeah. So like, like Ray mentioned, you know, we are looking at the values that, that Rubrik Security Cloud is applying on the, on the,
07:25
backups that it takes. So it's saying, "I found something. I found an encryption event. I have an anomaly." it's saying, "I You quarantined an item," and, we're directly translating that into, tags that show up in our, our FlashArray UI. And that's a big piece of this, is you don't have to go searching for things.
07:47
They're right there in front of you. We have a nice little Rubrik button. You click that, and, and you just see all the things that, that have happened from the workflow. Since it's, you know, it is a workflow, it's automatic, and, you don't have any partic- any
08:01
specific actions you have to take as an administrator. So, you know, it's very turnkey from end to end. Yeah, that's great. I think that automatic is kind of an important bit of that too. And I am gonna pause the slides. Apologies to those who love the slides, but I think the audience would like to see a little
08:18
bit bigger picture of Ray and Roy. I like to think so. So let, let's, let's dive in and talk a little bit about the questions. Thank you both for that explanation. I think it made sense. Obviously, we've got Q&A out there, so if people do have questions or wanna dive a little deeper into something, you know, we've
08:32
got the people that know how this work, on the phone. So let's talk about how do we eliminate some of this recovery guesswork, right? And what, what I hear, and I literally just presented to some of our new hires, and we talk about things like when somebody gets hit, the average days to recover is 24 days. 24 days to recover from this, right?
08:55
And I don't think many businesses can kind of withstand being down for 24 days. And what we find with that, a lot of it is just trial and error, right? I, I do a restoration. Oh, well, that one's not clean. I've gotta go do another restoration, and this kind of keeps going.
09:10
So if we think about how this fusion of Rubrik's threat intelligence, right, those scanning of those indicators of compromise, and that correlates directly with what we bring to the table with Pure, and, you know, I'll throw out a, a word, SafeMode. If you haven't heard of that, we're happy to explain it, but our SafeMode SafeMode protected snapshots.
09:27
How does that really eliminate some of this uncertainty and drive us towards this, you know, near-zero RTO term? Ray, I don't know if you wanna take a first stab at that one. Sure. Yeah. Love that question too. The scary part is that the recovery process is really a bit of whack-a-mole today.
09:46
You said 24 days, and what customers are actually doing during that 24-day period is trying to find clean data in their backup catalog so that they can overwrite the infection, and there's a lot of trial and error involved in that. I've gotta spin up recover points, hope that they're clean. If they're not, I reinfect my entire environment.
10:09
That's the, the beauty of this that, just by simply protecting this and letting these, these, threat analytics do, do their job, we can quarantine the data and outline the blast radius in our catalog and in Pure's. So if you wanna use the snapshot for recovery, the recover points that are secure vaults or what's sitting over in, the FlashBlade archive, any one of those,
10:41
you can recover with, with confidence that the first time and every time that recover that, that object, that you're getting a good, clean point in time. That, that clean point in time is so important. One, I was sharing a story, of a company out there that actually got, got hit twice, and we hear these stories. They come up occasionally, and, and sometimes
11:03
they get hit twice because these threat actors will sell their access, right? And somebody else will come in. But actually, a lot of times it's what you're talking about, Ray. They, they didn't find a clean copy of the data, and they actually restored that malware that actually ran the encryption in that first place.
11:18
So that, that clean-room copy is, is really important. You know, R- Roy, what are we doing? Maybe even dig in on the SafeMode perspective for a little bit. How does How do we take what Rubrik's feeding us and use that to help customers recover faster? Yeah.
11:33
So like we've been saying, knowing upfront what, what good data looks like, is important to not having to hunt for it, and the you have to hunt for it, the more times have to recover data, test data, redo that, you know, that, it, it, that's where the 24 days is coming from, right? So the, the workflow is, as I mentioned earlier, it's going on talking to RSC, and
11:58
it's saying, "Tell me about the backups that you know about for my array," or my array, my Fusion fleet really, sort of we're integrated with at the fleet level. Um-Whether they have SafeMode or not, it's gonna behave the same way, right? We obviously want them to have SafeMode because then we know that somebody's not gonna come and maliciously delete your snapshots before you can use them.
12:21
But we will go out to RSC, and we'll say, "Tell me about the backups that you, that you know from y- my fleet. Tell me if they have any quarantined items, tell me if they have any anomalies in them." And then we'll translate that into, you know, we have this snapshot from this time, that relates to that backup, and we'll, say, "Hey, the backup had, you know, this
12:46
thing in it. It had quarantine, it had w- had an anomaly. You should know about that as an array administrator. Let me tag that for you and say, 'Rubrik found this thing, and we found out about it at this time.'" Right? And that way you can go into your snapshot list and say, "Okay, I've got these snapshots that are, that are tagged,
13:07
this other snapshot that isn't tagged. So I can be confident that this untagged snapshot is clean from Rubrik's perspective. Rubrik did not find anything, you know, that would make us say, 'Oh, there's dangerous on here.'" from there you, as an administrator, can use that snapshot to, you know, recover the, set of VMs, a data store, you know, what have you.
13:31
Using, using Pure's orchestration methods can be very, very quick, and, and, and really, almost hands-off, which is fantastic, when, you know, you've got a million things to do when you're under attack. Yeah. I mean, from, from, from the other you know, as Ray says, you know, you say, "Oh, I, I need to get back something from one of
13:58
these timestamps where I, I don't have good data," right? I mean, where I don't have known clean data. But I don't wanna, I don't wanna risk back what, you know, Rubrik found, so I'm gonna go to Rubrik and do a surgical recovery of just that VM. Or I have critical data that's on this VM, I can, you know, pull that back without,
14:17
affecting anything else. Yeah, exactly. You know, Ray mentioned the word layered earlier, right? We talk about that layered approach. You know, if we can recover from these Safe Mode protected snapshots, we wanna do it. It's our fastest way.
14:30
But perhaps we didn't have enough retention of that, right? And all those snapshots maybe Rubrik identified, all of them have some kind of indicator of compromise on it. I can go back to that Rubrik, environment that's gonna have a little bit of a longer term retention than we're typically gonna keep inside the array itself, and do that surgical
14:47
recovery just of those systems that I need to. It's a great point, Roy. You're, you're kinda getting into our next question a little bit as well, so I'll, I'll kinda stick with you here. But i- if you think about the history of storage, we, we've kinda been a target for these attacks, right? It's where the data lives.
15:01
It's where it actually physically becomes encrypted, unusable. A lot of times they're going after and deleting this data. But with, with this integration we're about, we're trying to move that STaaS being passive to an active part of that defense. So keep going. You kinda started down this path, but can you
15:19
describe a little bit how that automated tag, again, the automated's kind of important, really affects the volumes in Pure Fusion. And keep rolling down that path. What does that mean for the storage admin? What did it look like kind of before, what is that role of the storage admin?
15:32
How does it change, and how do we enhance that with the new integration? Yeah. So before you would've, you would've had, to have, you know, people kinda tag team, right? You'd have to have, a, a administrator from a system side come in and say, "Oh, I need to get this system back," or, "These s- this set of systems.
15:53
Hey, storage admin, can you help me figure out where this actually is?" would say, "Oh, okay. Well, let's, let's figure that out." And then we'd have to go to, you know, restore a snapshot, and that means the storage admin has to take actions on their side, system admin has to take action on their side, and, and then hope they find the data they need.
16:13
You know, or if they have to go back again, you know, it, it becomes an increase every single time you have to execute that. So now you are bypassing all those retries. But on top of that, you know, you also have the potential for the, the systems admin, you know, in, in the VMware case, you know, if they're using our storage,
16:36
our, our, plugin for vCenter, they can see, you know, the, the snapshots themselves. So they can, and they can restore from those snapshots. So you can even bypass the back and forth, or at least a lot of the back those two teams, and shrink the recovery time even further. You can say, "I can I, I'm a VMware admin.
16:56
I'm I, here's a snapshot. Hey, storage admin, is this clean?" "Yes, it's clean." "Okay, I'm gonna go and, and restore the data I need from that snapshot. So I mean, that's, that's one way. From the storage admin's perspective, you know, they would, they would've seen a list of volumes, they would've seen a list of snapshots for those volumes,
17:16
and that's about it. They can see when the, when they happen. They can't see anything else about them. And- So it's really, Roy, I think you're- Mm-hmm you're expanding beyond just the identification of, you know, clean and not so clean data. We're, we're giving you visibility into how this environment is kind of laid out, right?
17:33
Mm-hmm. So you, you, we, we mentioned earlier trial and error, but it's also the back and forth between the different teams, right? We're eliminating some of that back and forth that needs to happen to make a recovery effort possible. Yeah. Ray, Ray, I'm gonna flip that same question to you, but- Go for it the changes, what, what
17:48
about for the CISO? What does this mean for the CISO now? What's different for this individual, we're talking about restoring from a breach? Time to recover is the most critical element here. And, you know, Roy alluded to this a little bit. I, I spent quite a bit, time in IT before, joining Rubrik, 18 years to be exact.
18:10
And-There are silos. You know, if you're in a really small organization, you might be in a scenario where, one person is wearing many hats and has, you know, access to what the s- the security tools are telling them, access to what, the, the storage platform can see, to what the, the backup catalog is, has access to.
18:32
But the beautiful part here is that we're sharing all of that information with everybody proactively so that, if it's the InfoSec team that gets the alert first or chooses to respond, they can, they can start the, the recovery process. If it's the storage administrator, they don't have to wait for permission for some, you know, backup admin to, to, to point them to a point in time in their, their, their catalog.
19:00
They can start a, a recovery process, entirely on their own. The, the visibility to the, to the same set of information is arming that CISO, is arming that InfoSec, it's arming that SOC team, it's arming that backup administrator and that storage administrator with the same level of information, and letting them take action, immediately to reduce that downtime.
19:26
Absolutely. Let's, let's keep going down that theme a little bit, of, of that visibility, and also breaking down silos. I mean, we, we see this all the time when we meet with customers. The security teams and the infrastructure teams, they have their own worlds, right? So, you know, they're doing different things.
19:42
They often don't talk to each other as maybe we would like them to in that world. And that lack of communication, Roy, you were hitting on this too, that lack of communication between let's call it like a SecOps-type team, InfoSec, whatever you name it in your organization, and the infrastructure people, who are generally responsible for a lot of the recovery efforts, just doesn't happen, and that causes delay too.
20:03
So if we think about and drill in, and I, I think there's a couple things you wanted to mention around this, but how does this round trip integration, if you will, between Rubrik Security Cloud and Pure1 create a more common operating picture? And how does it do that at scale? Yeah. So, one of the things that we, we haven't
20:22
really talked about a lot i- on this, this, session so far is, is Pure Fusion. Pure Fusion is our capability, excuse me, that, lets you from a single array in your see information and manage information and configurations on any array in that same fleet. So you have the, the, the true single pane of glass. And the integration with Rubrik Security Cloud has tied into that, right?
20:50
So, no matter how big your f- your, how many FlashArray you have, you have 1touch point from the workflow, you have 1touch point as an admin, and you can see all of the information that the workflow has applied. All of the tags are visible from one place. And on top of that, we have this, this of workloads that we've, implemented as part
21:13
of Pure Fusion, and that basically says you can define, you know, a set of a storage, a storage configuration, right? So I, I have a, a data store pro, workload that I define, and I've used that to provision a bunch of d- of, data stores. We also tag at that level, right?
21:34
So I can see that for, you know, let- let- let's say I've got a SQL data, a SQL data store profile, or workload. I can see that I've got that workload affected. I can drill into that workload and see what volumes are tied to those data stores, and I can see which of those data stores have been affected by whatever Rubrik detected, and I
21:55
can see which snapshots of those volumes are, are affected. And I can do that from one management point without having to go to a bunch of different systems if I have a large environment. And, and there's a huge amount of power in that. Like I said earlier, when you're, when you got a million things going on and you're under
22:12
attack, that, you know, you don't wanna have to go and hunt for things. There's, it's going to kill your recovery times. Exactly. A- anything we can do to reduce potential delays in that process is big and, you not everybody has hundreds of arrays, but, know, maybe you got five or six or 10.
22:29
Obviously, data continues to be more important. We think about AI, for example. What, what does AI need to effectively function? It needs a massive amount of data, so people are storing more and more than ever. So to Roy's point, if I can get that visibility and cross my entire data estate in
22:44
one place, I am really reducing, you know, the amount of effort I have to for this information, right? So Ray, I don't know if you had any comments before we move on to the next question, but is there anything you wanted to add to, to what Roy said? Roy nailed it. It's about, crushing those silos and making
23:02
that data available to, to everybody, and giving folks, security at the, at the point of data. Instead of, you know, requiring some other team to, to hop in and save the day, you get to participate in your, your own rescue, which is pretty cool, if you ask me. That is very cool. So, so far I think we- we're helping break
23:25
down silos, right? That's always a good thing. We're giving visibility across the entire data estate to security teams, to infrastructure teams, to all these folks that have to be involved in a recovery effort, and we're reducing the amount of time it takes to actually find a clean-room point of time to actually go recover from your environment, right?
23:44
So a lot of great things. There's still kind of a big thing I will say that we, we haven't touched on quite as much, which is what about the performance side of things? Like, we kinda did hit on it a little bit but, you know, if we, we talk about amount of scale, and sometimes it's PB scale, and we're, we're, you know, we have
24:02
customers we see that are in the exabyte scale, crazy enough sometimes these days. But even if you've just got hundreds of terabytes, that data movement sometimes can be a problem. There's hardware limits. Roy, I'm gonna go back to you a little bit, but with that capabilities that we have inside of the box-How does this joint solution make sure that even petabyte-scale attacks don't
24:25
end up becoming weeks-long outages? Yeah. So we, we talked about the speed of snapshots and, you know, what is that speed and why does it exist? You know, snapshot is not a copy of data exactly. It's, you know, it's a, a copy of references to, to data, right?
24:43
So that I've got a picture of where is all my data in my storage, and that's my vol- my live data. Now I've got a snapshot. Oh, it looked different at this time, and, and now those pieces are in these other places. If we had to copy the data from one to another, it takes, you know, time.
25:01
We're bound by physics of moving data you know, between FlashArray or across what have you, and, you know, those physical limits are relatively low. And if we just say, "Oh, I'm gonna create a writable copy of this set of references," I can do that in less than a second, no matter how big that data is. You know, if I've got a petabyte volume, great, I just copied it in less than a second.
25:30
If it was 10 TiB, great, less than a second. You know, couple gigs, less than a second. Doesn't matter how big it is because all I'm doing is, everything's, you know, memory operations, and memory is not the same, the same problem of, of moving things around at all.
25:46
And you know, nothing against Rubrik, but Rubrik is gonna be bound by physical limits, right? If we've gotta move data from, from back to, you know, through, through that are kind of outside both of our control, you know, we've got a lot of, in the middle that we just don't have when everything is inside the Array's memory and
26:06
nothing has to, has to go anywhere. So, yeah, like instantaneous recovery, is only possible with, you know, snapshots. Exactly. And we, we say instantaneous, right? There's, there's always potentially steps in there that you've gotta take, but again,
26:23
that's, it's kind of back to our friends at Rubrik. Like, Ray, how do we, how do we get to this point of a, quote, "near-zero RTO" in this case when, you know, you don't wanna randomly start restoring data, even if the ability to do that? Laws of physics be damned, right?
26:40
Roy hit the, hit the nail on the head. Even the fastest and broadest stripe of Rubrik is only recovering, I won't say only, is recovering in parallel at a rate of 300 to 400 MB/Sec per node. So when you apply that to a workload that's potentially tens or even hundreds of TiB,
27:09
it might just make more sense to pull it back from a, from a snapshot. You know, we're, we're trying to, to get workloads back into production as quickly as possible, and it's really about finding the right tool for the job and doing that process as quickly as, as is humanly possible. And that's why we built the threat monitoring piece the way that we did.
27:32
It works proactively so that when that SLA domain and the scheduler that's underneath goes and grabs that recover point, I don't need to tell it when or how to scan that data and make sure that it's clean. It does so automatically as soon as the data comes in. And we're trying to proactively cleanse the catalog itself so that if and when you need
27:57
that information, it's available for you to per- perform that recovery. It's already identified the blast radius around that attack in our catalog and shared that exact same data with our friends at, at Pure so that if I'm pulling from bucket A, B or C, I have confidence that the data that I'm gonna put back into production isn't gonna unleash the same virus, the same compromise that's been plaguing my business for the last,
28:28
last few days, the last few hours. You look at this prevalence, like the growth of I mean, I think we've all probably heard the term IRE a couple hundred thousand times in the last, last six months. Gang, this is why people are creating IREs. An IRE is a really fancy, newfangled term for don't let the cat out of the bag.
28:47
I've got something that I'm not confident in, and I need to spin it up so I can do an analysis. With an IRE, I'm just fencing the, the of that, that network bubble so that I can perform that analysis without reinfecting my production environment. And the beauty of our platform is that we're performing that analysis without sharing that
29:09
data with anyone. We don't have to create some NFS share or give some third-party product access to, to, to, to the data itself. We're ingesting the Mandiant feed, and inside of this bunker in a box in these Rubrik secure vaults, applying that ourselves to what we see in the catalog, quarantining the things that give us concern, alerting your InfoSec
29:32
team, alerting your backup administrator, and now alerting your primary storage administrator of the location and severity of that possible in- indicator or compromise so that those folks can hop in and participate the recovery. That's really good stuff. All right, we're gonna move to some audience
29:55
Q&A, but just a little bit from that summary, right? We're, we're breaking down those barriers, again, giving visibility to everybody across the entire data state, right? That's where the Fusion comes in. Rubrik is bringing their, you know, great, really rich threat intelligence information
30:12
into that environment, so we can see that in the production data, right? Not just the backup data, but actually see what that looks like inside of our production data. And then the combination of those things is allowing us to perform even at petabyte scale-Very, very quick recovery. So we all know when you get hit, the only thing your executives wanna know is how fast
30:30
are you getting me back in business, right? Right. So the combination of this is really powerful. So I, I see we've got a few in the Q&A. We'll see how this works. I'm just on my little laptop screen today, so I'm, I'm trying to manage a bunch of different little, screens going on.
30:44
There's, there is a question about supported with, Proxmox. Don't think there's quite a, plan per se for that, but Ray, Roy, if you guys know any more, if that's one we can address. We Hey, we are all for feature requests, gang. Okay. I think we had talked about adding this for, NAS was, was the next target.
31:06
Unstructured workloads is kinda what we were thinking, it's what we've been hearing from customers. Also, adding the same functionality for security operators on the Rubrik side, so like sensitive data. Doesn't need to necessarily be an infection.
31:21
I'd love to be able to tell, like, a, a, a, a storage administrator, "Hey, some- somebody copied, you know, HIPAA data into a, a, a backup share by, by accident." but no, no Proxmox has been specifically discussed, just yet. But if you guys tell us, that's, guys and gals tell us- Yeah that's the direction we need to go, we're all ears. Obviously demand matters and, and look, there,
31:46
there's been a lot of debate about VMware. I'm sure we, we actually probably have some webinars on that one too. You know, if, if there's good market demand for the Proxmox, obviously there's a good bit of alternatives out there to VMware, but VMware still owns that large market share. So that, that was kinda the first start, at least from the virtualization
32:03
perspective out there. And, and of course unstructured data, you know, we didn't hit on that today. We, we probably if we don't should get a webinar on the schedule for that one. You know, that is, that is where we're a ton of data growth, especially with like AI and how, you know, our combined solution can kind of help there.
32:19
So I'm gonna move on to the second question. I'm just gonna try to, try to read it here. So let's say Rubrik identifies an issue within one of Pure Snapshots. Great, I know which snapshot it is, so if I need to recover I know maybe not to use that snapshot, but are there any options myself as an admin to tell Rubrik to dive into the
32:36
snapshot and triage the issue, or is that not a current capability? So- Not a cur- what he's asking is, can I then- Analyze the snapshot itself? E- exactly. Oh, man, I l- I love that. I'm gonna, I'm gonna quote you, my friend, whoever that was, to my, my product management team.
32:54
We, we, we've had, numerous discussions about doing exactly that, how to, how to take the backup out of the picture and just use the threat analytics directly on, on the volume and on the snapshot itself. Nothing concrete for you yet, but we've got some of the brightest minds on the planet working together- Yep to see if we can make that a reality.
33:16
That's definitely on our mind, obviously. You know, sometimes the development takes a little bit and, and there's resources involved in all this, but, you know, I think that is kind of an at least an aspirational goal at the moment to do that. And then I think this was from the chat, but kind of a little along the similar lines.
33:31
Maybe, Roy, you can take this one. I hear that you mount VMs in Rubrik and then scan the VM file systems for Mandiant indicators of compromise. Is that right? This isn't just metadata or entropy tests. So there's a couple things in there, Roy, if you wanna go ahead and address that one.
33:47
I'm actually gonna kick that one over the fence to Ray since it's- All right, okay. We're good. I know, I know Ray's got this one queued up in his head already. Does he? But- All right, go ahead. I'm sure he does. Talks about this all day.
33:57
I love it. Oh, my, my, as my wife says, I love hearing myself talk too. So we've got a, a, a, a few different ways, that, that we can, find clean data for you. So there's anomaly detection, which is looking for entropy. It's looking for anomalous change rates.
34:15
We've got threat monitoring, which can take the Mandiant feed or your own, or a combination of the two, and scan that against your catalog. We've got threat, a- advanced threat hunting, which is similar but more surgical. I can take YARA rules or file hashes or paths, select any number of recover points in my catalog and say, "Show me this YARA rule
34:43
across these recover points right now," and it'll go mount them and do that, that, that a- analysis real time. And then last but not least, we have turbo threat hunting. So when everything passes through the system and threat monitoring is turned on, we fingerprint all the files just to be SafeMode.
35:05
And even if we don't find some kind of infection, that goes in our hash table, we hang on to that data. If you come back to me six months later and that data has moved to an archive, whether that's a FlashBlade or a Rubrik Cloud Vault, out, out in Azure or AWS, we can find that file hash across the fleet, every recover point in your
35:33
catalog in roughly 60 seconds. You could literally have tens of thousands of recovery points in your catalog, and it's going to do this real time search and show you where that, that file exists. So that's really gonna be useful for a zero-day attack, for example. Most of that Mandiant feed, what a lot of folks don't know, I think somewhere like 85,
35:53
90% is actually hash-based, indicators of compromise. So, when new ones come out, they're by and large, file hashes, and we'll go find them across your catalog. Yeah. And obviously I think you said, what? Over 1.3 million in that database today, so it's- Yeah, I heard somebody say 1.6 the other day.
36:13
I'm not The number's growing. I, I, I- Well, the good news, bad news. Bad news 'cause they're growing, but the, the good news is that they obviously do this very quickly and they keep up with this. They can identify attacks, very rapidly.
36:25
I'm gonna skip over a couple questions that I will come back to simply because they're probably gonna be questions for Ray again. And I'm gonna give one to RoyUh, al-although Ray's gonna have to answer this too, but Roy, from the Pure perspective, what licensing is required to enable this functionality? It's a great question. So from Pure Storage perspective, you need to be a
36:43
Pure1 customer. So basically you just have a, a valid subscription. You don't need any special, any specific licensing tiers or anything, but you have to be a Pure1 customer. Yep. How do, how do you become a Pure1 customer?
36:59
That's a question for you, Scott, as a sales dude. So here, here's, here's the answer for us. You, you just buy Pure Storage. Yeah, exactly. So that, that is one of the things with us, we don't do a lot of licensing additions and things. When you buy Pure, functionality for the box
37:12
itself, you, you get as a good Pure customer. So that, that includes things like Pure1. If you are an existing Pure customer, you do need to enable Pure Fusion. That is not a cost to do that, right? Okay. It's just something that your, your local SE can help you walk through.
37:26
It's extremely quick. You can do it yourself, but if you want a helping hand, you, you can do that from your SE. Ray, from the Rubrik side, what kind of licensing is required to make this whole fun thing work? Enterprise Edition.
37:39
So that's gonna include, the, the, the, the threat analytics I talked about, the anomaly detection, threat monitoring, advanced hunting, turbo threat hunting, and also, sensitive data discovery for your, your catalog. Once you have that, turn the integration on, configure it for your, for your fleet, you're off to the races. Excellent.
38:01
All right. Now, backing up a little bit in the question order, this is from Joel: "Did I hear earlier that in the event that all snapshots that are being retained are compromised, that stored on Rubrik..." So let, let's call them backup copies for this purpose. I know some overlapping terminology, but those copies stored on Rubrik could be used
38:21
for a targeted restore. Yeah. So if everything on the Array is compromised, I can go to Rubrik and do a targeted restore. Yeah. Well, keep in mind, gang, while you can use SafeMode Snapshots, while they You know, we talked about all the benefits of them let-
38:40
moving massive amounts of data back into production. Rubrik was purpose-built to keep your entire backup catalog for eternity. So Pure's not gonna h- in all likelihood, have seven, eight years' worth of- No you know, with the recover points. It, it, I'm sure your, your, your Pure rep would love that if you, if you did it.
39:01
But Ru- with Rubrik, you know, if you're have copies on us, you can keep, you know, number of days, a single day, six months, doesn't matter. There's no limitation there. Move that data off to the FlashBlade or out to those archive for, for longer term storage, to help drive down cost.
39:18
And so if the, the, the catalog that you have doesn't go far enough back to clear the infection in Pure, you still have the option to pull that data through Rubrik and, by proxy through, that, that FlashBlade archive. 100%. So, you know, you're, you're gonna do a pretty, a pretty good bit of retention of the snapshots, but you're not gonna do that
39:39
forever in production, even though we can, we can store a really long time on that. So Rubrik, to Ray's point, is gonna keep that catalog and potentially a pretty good bit of data. And then for, you know, let's call it TCO perspective, if you do wanna keep months and months or even years, sometimes we have regulatory requirements for that, we can put
39:57
that on something like a FlashBlade to help reduce that cost for the long-term retention. And any of those places are all available for restoration, so if the snapshots don't work, you've got that whole entire Rubrik catalog of restore points to choose from to get you back in business. So great question, Joel. Don, or I'm sorry, I think it's Don Wang.
40:17
I don't know if I'm saying that right. Apologize if I didn't. But, "How does Rubrik access SafeMode Snapshots on the Pure FlashArray?" So this is getting into, hey, we're tagging these snapshots, but how did, how do we know to do that in the first place? Great question. What we're actually doing is trying to
40:34
correlate the time of the infection to the catalog itself. So we're focused on the primary volume and cascading what we see as dirty from the volume down to the snapshots that were taken around the time of the infection as well. Roy, you could probably do a much better job of explaining that than I did maybe. Yeah. So there Rubrik isn't actually accessing the
41:00
snapshots directly, right? It's the, the, Pure1 service is connecting the dots between the two. It's talking to Fusion, to, to do the tagging. If you wanna use those snapshots for recovery, that's outside of Rubrik. You're gonna do that with native tools, you know, native FlashArray tools, native VMware tools,
41:20
and, you know, eventually as we add workloads, tools from those workloads as well. Now, that's not to say we won't ever, you know, build more integration on that, but that's the, the state of things. Absolutely. And just speaking on integration, right? I mean, you know, our, our partnership, we'll call it, is relatively lo- young in terms of
41:39
this particular group working together. We've already done some amazing things, but I think we, we may have hinted at that we're, we're continuing to work on, so stay tuned. If this isn't enough for you, stay tuned. There will be more coming.
41:53
All right. Getting a little deeper into some of this, and we'll, we'll see what we can answer today, but it might be something to, hey, just go back and work with your, your Pure or Rubrik SEs. But Christopher asked, "We use Rubrik for backups, and we have Pure Storage." Thank you for being a customer of both of us, Christopher.
42:08
The arrays are set up in Rubrik under Data Sources, Storage Arrays. Is there anything else we need to do to make this integration work?" I don't know of you wants to take it. I'll take that one. Go ahead. So you, you actually don't even need to do that. Like, we love that you're using the snapshot
42:24
integration to, to, power your backups, but, regardless of whether you have Rubrik orchestrating snapshots or not, the, the work is, the, the workflow integration still works. And the, the snapshots that Rubrik is as part of those backups, it's deleting as part of those backups, so there's really nothing left by the end of those backups for it to tag in the first place.Excellent.
42:51
So if that didn't answer fully enough, you know, feel free to reach out to us, reach out to your Rubrik, your Pure SEs. We are happy to, to help walk you through this from an integration. All right. That's all I see in the Q&A window- Yeah but I think there were some indications there might be some in, in the regular chat.
43:07
I don't know if, uh- There probably anybody- Scott, if I could just make Yeah, please go ahead for folks that are interested. Gang, this thing went full-blown GA late December. We, we, we, shouted it from the rooftops on January 20th. If you're interested in this, we are interested in helping you turn it on and
43:27
configure it. We wanna make sure you have a great so don't hesitate to reach out to your Pure rep, don't hesitate to reach out to your Rubrik team. We'd love to help you get up and, up and running. Absolutely. Michael Frank an- asked a question that I
43:46
think we've kind of already answered, but just to reiterate. He asked, you know, "How much more does this cost if we already have Rubrik Enterprise and Pure?" The answer in that case is nothing. If you don't have the Enterprise, then obviously it would vary on your particular environment.
43:59
But for our customers that are already have these independent capabilities, little bit of your time to get this magic working. Let's see what else we had inside of this. Is Pure Fusion included with Evergreen//One? It, it doesn't matter to us at Pure how you procure it, if you're a Pure1 customer, customer, whatever it might be, Fusion is
44:20
there and freely available to all of our customers with a couple of little tiny steps that are actually very quick. Even, even somebody like me has been able to go through and do it. Really easy to do, but again, your SE can easily help you, do that. Any limitations," this is from Kate.
44:36
Any limitations on snapshots? How close together can snapshots be taken? Any data limits?" Roy, I'm gonna throw that one to you. Yeah. So the arrays are capable of, I believe, a five-minute granularity on snapshots.
44:51
Most of the customers are gonna do it probably hourly or more. It's, it's kind of a function of how many snapshots can you support without, you know, without hurting the performance of your workloads. You know, the array itself can h- hold 100,000 snapshots, so, like, that, that's not the, the limiter.
45:10
And there isn't really any limitation on how many snapshots are you see between backups. The, the workflow is looking at when did my last clean backup occur? When did my, you know, dirty backup occur? When do I see these indicators of compromise? And what snapshots would be affected by that based on the timing of when, you know, all
45:31
these things happened? And so if it's, you know, one snapshot, if it's 1,000 snapshots, doesn't really matter. All right. Excellent question. So take lots of snapshots, right? And I say that because same comment as Ray earlier, your sales team will, will, love you
45:48
for that. Although to be quite frank, yes, snapshots take up space- Yeah but our snapshots are super efficient, so they actually don't take up that much space. So your sales rep may not love you as much as they would like to think that they do. I think Michael Frank has one.
46:02
Let's see if I can read this one right. If I replicate Pure snapshots to another Pure Array in another data center," let's say maybe they were doing things for, from a DR perspective, "can we pull those back to recover and Rubrik see it?" So, Rubrik seeing it, not really. Rubrik's not gonna be aware of that.
46:23
But as far as you s- having the, the, the tagging, in most cases, yes. What happens is if you're using ActiveCluster or Active DR, the snapshots replicate, and they, the tag goes with them. If you're using asynchronous replication, it depends on timing. The, the workflow won't, tag the snapshot that was already replicated, but if a
46:49
volume, you know, the, the live volume is tagged as having an anomaly or a quarantine, and then you, you know, a snapshot happens with a replication, that tag will follow the, the snapshot. Absolutely. So hopefully, Michael, that makes sense to you. But yeah, I mean, the, the, the basic answer is y- your, your setup and things are good in
47:09
that tagging. If you think about that Fusion fleet capability sitting across everything, you'll get that. One from Scott, and I think we may have something, out, out there that will show, you know- something. But if not, Scott, you know, reach out to your, your Pure sales team.
47:24
We can definitely get you the additional documentation. He asked about documentation as talking points for his leadership, so we're to help you that. All right. This is actually Well, it's a comment, but I think I'll read it.
47:36
I think it's a good comment from Dustin. Balancing transactional consistency on busy data s- bases is a thing about mini snapshots." So certainly, like, the that or, or let's say more the frequency of that sometimes can definitely be a thing, because a lot of people like to worry about that consistency. I will say, Dustin, if you reach out to your,
47:54
your Pure sales team, there's some database type resources who actually love having that particular conversation and can dive into all the details of ya. So with that, let me see if I can share up, our slide again, if I can find where that guy went to. Not, not to give you all more slide work, but I think we end up with a
48:19
through this. We already answered questions. A couple quick mentions out of this. We are gonna be at the RSA Conference, so that's the week of March 23rd. We have a booth this year for Pure Storage. Rubrik does too. Ray, I didn't actually get that back from
48:33
anybody, so I don't know if you know what the booth number is, but I'm pretty sure you guys can look that up and find it out. For Pure, it's 2449. Please stop by. We'd be happy to talk to you about this and anything else we do in Pure.
48:45
And obviously make sure that you m- visit Rubrik's booth as well and, and start to get demos. I am pretty confident that they're gonna show a lot of the things that Ray discussed today. Join our Pure Community, right? People were looking for documentations, looking for discussion.
49:01
We have blog posts, we have discussions with customers, lots of information out there on side of our Pure Community. Make sure you take a, a stab at that. And with that, I think we are done for the day. Ray, Roy, any final comments as we wrap up our webinar this morning?
49:18
Download the white paper. If you're looking for any detail on how any of this works, you wanna share any of this information with folks at, at work, with, the boss, there's a white paper, there's a data sheet on it as well. I think we even got some blog posts on similar.
49:40
Don't, don't hesitate to hit up rubrik.com, purestorage.com. You'll find all of that available. Absolutely. Both available on both of our websites. Again, thank you to both of our guests today, Ray and Roy. Excellent job. I think we shared a lot of valuable
49:55
information with the community. And with that, thank you to all of our customers, and hopefully future customers, there's some of those out there, for joining. If you need more, hit up your local sales team, hit up our website, hit us up personally. I think we're all on LinkedIn.
50:07
We'd be happy to have a conversation. And with that, thank you for your time. Thank you.