- CheckMates
- :
- Products
- :
- General Topics
- :
- Automatic deletion of logs.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Automatic deletion of logs.
Hello,
What is the best way to "determine" if my SMS is deleting my oldest logs?
What we want to know is, if we can have a control over the logs, to avoid that the path where the logs are stored, fill up and saturate the SMS disk.
How many days by default does an SMS store logs when it has a Cluster attached to it?
Greetings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Options exist within SmartConsole to control retention behavior, typically this is based on remaining space metrics either capacity threshold or percentage based.
Other metrics aren't so uniform and might vary significantly from one environment to the next based on logging rates / volume of managed gateways etc
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I would like to find the oldest logs that are stored in my SMS, and be able to "export" them to an external device.
I understand that the oldest logs, I could see them in the route of
"cd /var/log/opt/CPsuite-R80/fw1/log", right?
We want to find a way, for example, that the SMS only stores the last 30 days of logs, and that after that time, it can "overwrite" them automatically, so that we have control over the storage.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See https://community.checkpoint.com/t5/General-Topics/Define-log-retention/m-p/54642#M10915 for the settings. Manual check can be perfomed by looking into $FWDIR/log/ directory on Security Management Server.
