FAS · AFF · RAID-DP · aggregate · WAFL · multiple disk failure · VNX · Unity · Clariion · RAID group · pool · 520 · 528
NetApp and EMC arrays array recovery. Two arrays that format their drives like nobody else, in outline.
NetApp's FAS and AFF filers group drives into aggregates under RAID-DP, double parity on dedicated row and diagonal parity disks, with WAFL volumes and LUNs inside, and report multiple disk failure and aggregate failed when a RAID group loses a third disk. EMC's Clariion, VNX and Unity group drives into RAID groups and pools with LUNs carved from them, under FLARE and later. Both format their drives with extra bytes in every sector, 520 on NetApp and 528 on EMC, holding checksums a standard host cannot read, and both arrive here most often as a decommissioned shelf in a cupboard with one aggregate's data still needed and no filer to put it in. The members are the drive site's 520-byte job; the aggregate or RAID group is reassembled here from the translated images. Enterprise storage, from £1,250 + VAT after the free look, fixed in writing.
Rather talk it through? An engineer answers the bench line
0800 6890668
Models and versions we see.
Which level is it →| Family | Models or versions | Metadata, defaults and notes |
|---|---|---|
| NetApp | FAS and AFF; DS shelves | RAID-DP; aggregates; WAFL; 520-byte |
| EMC | Clariion, VNX, Unity | RAID groups and pools; 528-byte |
What tends to go wrong on a NetApp or EMC.
NetApp and EMC arrays symptoms, and how long each gives you.
Not listed? Describe it on the form →What the message means on a NetApp or EMC.
Describe yours to us →| What you see | The usual reason | Where that leaves you |
|---|---|---|
| Virtual or logical disk degraded | A member out; still readable | Image the weak drives before rebuilding |
| Virtual or logical disk failed or offline | Too many members out | Every member imaged; set reassembled from images |
| Foreign configuration | Metadata the controller does not claim | Do not clear; import only with every member present |
| Predictive failure on a survivor | Thresholds crossed | Stop; image before any rebuild |
From the parcel arriving to your files going back.
Work we have closed →Logged the day it lands, and the first look costs nothing Free
A case number goes on the parcel and a number on every member the day it is opened, matched to the slot you wrote on it. Each member goes on the imager its interface needs, never on a controller, and its metadata is read before a sector is: the level, the order, the stripe size, the event counts that say which member is current and which dropped out first. An engineer settles what has happened to the set and how much of it can honestly be read back. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.
Every member imaged, including the one that failed first
Every drive in the set is imaged sector by sector, weak areas last, on hardware that controls every retry, with a map of what could not be read kept for each. Members with failed heads go to the clean bench first; that is the drive site's work and the same bench does it. The drive that dropped out first is imaged too, because it still holds every stripe written before it dropped, and a rebuild that stalled part-way never reached them.
The geometry, from the metadata or from the parity
Where the controller's metadata survives on the members, the order, stripe size, parity rotation and data offset are read from it. Where it was cleared or overwritten, they are recovered from the data: parity across the members at the same offset should XOR to zero on a consistent stripe, which confirms the level and finds the stale member; where parity lands says the rotation; entropy at stripe edges and the file system's own anchors give the stripe size, the order and the start.
Assembled in software, and repaired on the virtual volume
The set is put together from the images in software, with nothing written to any of them: the current members in, the stale member used only to fill holes a survivor could not give. The file system is checked and repaired on a copy of the virtual volume, VMFS and CSV volumes opened and the virtual machines' disks extracted, databases repaired where they need it. The originals are not touched again.
You see the file list before you pay
What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.
From the bench
- Export the controller log first. It is the best record of what failed when, and the bench reads it.
- The drives are the job; the controller is context. Send it if it was replaced or holds an encryption key.
- Keep the first-dropped drive. It holds the stripes the rebuild could not compute.
What helps, and what harms.
Do this much first
- Export the log and photograph the screen
- Power down and label every slot
- Send every member
- Tell us the controller, the level, the stripe size if known, and what was tried
What sets us back
- Rebuilding with a second drive flagged
- Clearing a foreign configuration
- Forcing failed drives online
- Deleting and recreating the virtual disk
Questions answered before you commit.
The filer is gone and I have the shelf. Can the aggregate be rebuilt?
Yes. Every drive is imaged at native sector size and translated, and the RAID-DP group and the WAFL volume inside it are reassembled in software from the translated images.
Do I send the controller or the unit?
The controller only if it was replaced and the set is now foreign, or if it holds an encryption key. A NAS or DAS unit, only if its bridge holds the layout; the pages say which.
What does it cost?
Enterprise storage: from £1,250 + VAT after the free look, fixed in writing.
How long does it take?
5–10 days at the bench for a set of two to four; 10–15 days at the bench for larger sets.
Begin here if yours is doing the same thing.
Nothing gets worse while it is powered down.
Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. On most jobs an invoice only follows the data. Until that list reaches you, leave the server off and the drives in their slots.