RAID and server data recovery in Dunedin
For Dunedin, if storage fails, stop writes and repeated tests, note the exact symptom and identify the files that are essential.
- Case intake Gather the storage details, failure chronology, prior actions, encryption information and priority files.
- Technical diagnosis Determine the physical and logical risks and select an acquisition approach suited to the medium.
- Source protection Use protected images where possible to rebuild arrays, volumes and file structures outside the source.
- Result validation Test representative priority data, describe incomplete results and prepare readable files on healthy storage.
Preserve the set before replacing a member
A second warning during a rebuild can leave several plausible but incompatible states. Bay position, serial number, event time and controller messages should be recorded before disks are moved.
Each readable member is acquired independently so reconstruction does not depend on the array writing new parity.
For New Zealand NAS and server cases, bay order, controller messages, encryption and service dependencies are recorded before members are moved.
A hard drive that clicks, hunts or drops offline
Mechanical warning signs mean the drive should be rested, not put through another full scan.
A portable or desktop hard drive can develop unstable heads, damaged media or motor trouble after a knock, vibration or ordinary wear.
For a request associated with Dunedin, capture the exact sounds, last successful use and any physical incident. The drive stays closed while the connection path, electronics and mechanical condition are considered, and the most important data is identified before controlled reading.
- Power down when a drive develops clicking, scraping or repeated spin cycles.
- Keep the enclosure, cable and adaptor, but never open the sealed mechanism.
- Rank the required projects, folders and dates before extraction.
What to preserve with the device
Keep the original enclosure, power supply and adapters with an external drive. For NAS, RAID or recorders, label every disk by bay and retain configuration screens and alert logs.
Do not initialise a replacement disk, accept a repair prompt or save recovered files back to the source. Those actions can overwrite metadata needed for reconstruction.
Where stable reading remains possible, sectors are copied with limited retries to protected working storage; reconstruction proceeds away from the original medium.
Storage exposed to floodwater, salt water or a spill
Contamination and power are a dangerous combination even after visible moisture disappears.
Floodwater, sea spray and drinks leave salts or residue that can corrode boards and bridge fine contacts.
Remove power safely and record what liquid reached the equipment and whether it was operating. Different media require different cleaning and assessment; heating, shaking or opening a hard drive can add damage rather than remove contamination.
- Keep batteries, USB and mains power disconnected.
- Do not use rice, an oven, a heat gun or direct sun.
- Note the liquid type, duration, power state and any drying already attempted.
Validate content, not just directory names
Documents, photographs, archives and video containers require representative opening tests. Expected date ranges and folder relationships help expose incomplete files that still carry plausible names.
The handover identifies usable, partial and missing material without turning detection into a recovery guarantee.
Folder structure, dates and chosen formats are compared with the brief so damaged content, missing periods and unavailable keys remain explicit.
The stages of a defensible data recovery
Visible database files may still contain broken pages or a transaction chain that no longer closes.
A power event or interrupted replica can leave data, logs, and secondary files at different times.
Safeguard the source set, examine headers and log relationships on copies, and verify selected records. Report usable exports separately from unresolved inconsistencies.
Identify the database engine, version, local time range, and important tables. Successful startup is not enough if transactions or application records remain incomplete.
- Stop the database service and automatic repair jobs
- Keep data files, logs and configuration together
- Identify critical tables, tenants and the required recovery point
- Record the medium, chronology, attempts and essential files.
A practical brief for the diagnostic assessment
Interrupted footage can remain on a memory card even when its container will not open.
Many cameras write segmented video and finalize index data only when recording ends normally.
Safeguard the card from writes, reconstruct fragment order, and compare codec settings with a reference clip stored elsewhere. Verify the required time window after playback is restored.
For dashcam, trail-camera, or incident footage, retain the source card and document clock settings, recording mode, and the precise event period requested.
- Remove the card and engage its write-protect switch where available
- Decline repair or formatting prompts from the camera
- Record the camera model, resolution, frame rate and time window
- Last healthy use and incident sequence.
- Earlier restarts, scans, repairs or rebuilds.
- Essential folders, formats and date ranges.
Data recovery laboratory — Hard Drive Recovery in an ISO 5 Clean Room
For media arriving from Dunedin, essential folders, dates and access details are agreed before laboratory acquisition. The result is checked against those priorities and separates usable, partial and unavailable content.
Removing a hard-drive lid in normal room air exposes heads and platters to contamination. When internal work is warranted, ISO 5 Class 100 conditions limit added particles during inspection and component handling.
Assess mechanical warning signs without repeated power cycles
For Dunedin, clicks, delayed spin-up, intermittent detection and read errors must be recorded together. The drive stays powered down until electronics, heads and platter condition can be assessed, and clean-room opening is considered only for confirmed internal mechanical damage.
The source is not repaired in place. A sector-level or device-appropriate acquisition is created where condition permits, and every read limitation remains logged for later reconstruction.
File systems, containers, arrays or application layers are analysed on a separate working copy. This prevents an incorrect assumption from changing the only available source.
The result is checked by opening priority documents, media, archives or application data and comparing them with known dates and structures.
FAQ
Frequently asked questions
Is one cable change safe on an external drive?
Only when there is no abnormal noise, smell, heat or history of impact. Stop if detection remains unstable.
Why image a drive before repairing its file system?
An image preserves readable sectors and lets logical work proceed without writing repairs to the only source.
Should a hard drive be left running if it is still copying slowly?
Not when speed is deteriorating or errors are increasing. An uncontrolled copy may spend its remaining stable reads on replaceable files instead of priorities.
Is salt-water exposure different from fresh water?
Yes. Salt is highly conductive and corrosive, but every liquid incident still needs the media to remain unpowered until its condition is assessed.
Is locating the missing database file enough to declare recovery successful?
No. The file must be opened with the appropriate engine and checked for structural and business-level consistency.
Why will a visible video file not play after the camera lost power?
The container may not have been finalised or video fragments may be missing. Playability and timeline continuity must be reconstructed and checked separately. Compare the requested interval with camera clock drift.
Diagnostic assessment
Unsure about a storage device or fault?
Datastrophe assesses the risk before any recovery attempt and points you towards the safest next step.