Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
This widget could not be displayed.
1 Solution

Accepted Solutions
This widget could not be displayed.
7 Replies
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Jump to solution

Logs indexation 30 days R80.20 Take 87

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Hello everybody,

I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.

I follow the process as mentionned in the SK sk111766  and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.

Logs_storage_SMS.png

 

logIndexer.png

If someone had the same issue and have find a solution ?

Regards,

 

Campos Miguel

 

 

Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus
Dror_Aharony
Employee Alumnus
Employee Alumnus

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

Hi chico,

to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).

You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?

 

if still doesn't work, Email me with output of:

$RTDIR/scripts/doctor-log.sh

 

 

Dror Aharony ([email protected])

0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos
chico
Contributor
chico
Contributor
chico
Contributor
chico
Contributor
chico
Contributor
chico
Contributor
chico
Contributor

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

Hello Dror Aharony,

Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.

I send you the result from the doctor-log.sh

Thank you a lot for your feedback

 

Miguel

0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos
0 Kudos