Files backup
The workhorse job: folders on a machine, copied to storage on a schedule. This page is what happens inside a run, so the numbers in Run History make sense and the options do what you expect.
What gets backed up #
Every file under each source path, recursively, minus the exclusions. Symbolic links are not followed. Hidden and system files are included unless the switches say otherwise; the nightly template excludes cache and temp junk (*.tmp, *.log, ~$*, Thumbs.db, .DS_Store, desktop.ini) and the usual folders (node_modules/, .git/, browser caches) because nobody has ever wanted them back.
On macOS the agent also skips what Time Machine skips — cloud-synced placeholders, ~/Library caches, derived machine state and the ._* AppleDouble sidecars — so a Mac backup is the user's data, not a copy of macOS.
Incremental runs #
The agent keeps a manifest per job (manifests\job-<id>.json in its data folder) recording each file's size, modified time and the hash it uploaded. On an Incremental run a file whose size and modified time are unchanged is skipped without being read; one that changed is hashed and uploaded. A Full run ignores the manifest and uploads everything, which is what to choose after a restore, a destination change, or when you want a clean baseline.
Deleted source files are not deleted at the destination — a backup never propagates a deletion. Use version history to keep changed files' earlier copies.
Open files and VSS #
Use VSS takes a Volume Shadow Copy of each volume the sources live on and reads from the snapshot, so files held open by Outlook, a database engine or a user's Excel are captured as they were at the snapshot instant. Without it, locked files are skipped and named in the log. VSS is file-level consistency; for an application that must be quiesced — a VM, a database — use an App-consistent job instead. Windows only; on macOS and Linux open files are simply read.
Several source paths #
Each file's key at the destination is its full source path namespaced by drive: C/Data/report.docx and D/Archive/report.docx are two objects. The same rule applies to UNC paths (srv/share/…) and Linux paths (mnt/data/…). It means a job with three source folders never has two files overwrite each other — and it means the destination layout mirrors the machine, which is what you want when restoring.
Age filter and moving cold files #
Only files newer than N days keeps a job to recent work. Older than and not accessed in do the opposite, and with Delete source after upload they become a simple archive: cold files are uploaded, verified, then removed from the machine. Windows often has last-access tracking disabled, in which case not accessed in behaves like older than by modified date — never archiving something recently written. For folder-level rules with a catalogue, use the Archiving Policy instead.
Scripts around the run #
A pre-script and post-script (PowerShell, cmd or bash) run on the machine with a timeout: stop a service, dump a database to a folder in the sources, start it again. They are only available for Files jobs on an agent; a failed pre-script fails the run before anything is uploaded.
Reading the result #
A run reports files uploaded, skipped and failed, and bytes moved. Completed means every eligible file is at the destination. Warning means the run finished but skipped files it could not read — encrypted with EFS, held open without VSS, or blocked by antivirus — and the log names each with the reason; see Troubleshooting. Failed means the run did not finish, usually because the destination or the machine went away mid-run; the next run continues from the manifest.