Hi,
 
We upgraded our multi-domain infrastructure this past weekend and have started re-indexing previous logs that we keep online. We essentially set each domain's CMA to index back 14 days, then 28, 42, etc...
We predictably couldn't search for logs until re-indexing for that time period had completed but although we can now pull up logs for the time periods re-indexing has completed the reports and views still only show logs from after the upgrade.
NB: We did wait for re-indexing on the multi-domain log server to complete for the past 14 days before then initiating re-indexing on the Smart Event server.
 
Just to avoid ambiguity:
- On primary and secondary multi-domain management servers (primarily audit records):
 
 
days=1827;    # 5 years
for f in /var/opt/CPmds-R81/customers/*/CPrt-R81/log_indexer; do
  if [ `grep -c days_to_index $f/log_indexer_custom_settings.conf` -lt 1 ]; then
    sed -i "s/\(:max_disk_space_usage.*\)/\1\n\t:days_to_index ($days)/" $f/log_indexer_custom_settings.conf;
  else
    sed -i "s/\(:days_to_index\) .*/\1 ($days)/" $f/log_indexer_custom_settings.conf;
  fi
done
mdsstop;mdsstart;
 
 
- On multi-domain log server:
 
 
days=14;
for f in /var/opt/CPmds-R81/customers/*/CPrt-R81/log_indexer; do
  if [ `grep -c days_to_index $f/log_indexer_custom_settings.conf` -lt 1 ]; then
    sed -i "s/\(:max_disk_space_usage.*\)/\1\n\t:days_to_index ($days)/" $f/log_indexer_custom_settings.conf;
  else
    sed -i "s/\(:days_to_index\) .*/\1 ($days)/" $f/log_indexer_custom_settings.conf;
  fi
done
mdsstop;mdsstart;
 
 
 
MDS management servers re-indexed the last 5 years worth of logs for 50+ domains within half an hour. The log server took predictably longer. When that finished the next day we were sure to start the Smart Event server re-indexing after the log server had started on the day before and told it to re-index the last 15 days of logs:
 
 
days=15;
f=/opt/CPrt-R81/log_indexer;
if [ `grep -c days_to_index $f/log_indexer_custom_settings.conf` -lt 1 ]; then
  sed -i "s/\(:max_disk_space_usage.*\)/\1\n\t:days_to_index ($days)/" $f/log_indexer_custom_settings.conf;
else
  sed -i "s/\(:days_to_index\) .*/\1 ($days)/" $f/log_indexer_custom_settings.conf;
fi
evstop;evstart;
 
 
 
The Smart event and reporting server appeared to re-index the data from the log servers, producing a visible increase in inbound network traffic and CPU utilisation:


 
We subsequently increased the MDS log server re-indexing to 29 days (14 + 14 + 1) before subsequently wanting to then set the Smart Event server to re-index 29 days of logs in to the past.
 
We are now able to search for logs within the last week, for example:

 
We are however still not able to view reports for these time periods:

 
We can also confirm that the Smart Event server has indexes for the past two weeks that we asked it to re-index for:
 
[Expert@fwcpse1:0]# pwd
/var/log/opt/CPrt-R81/log_indexes
[Expert@fwcpse1:0]# du -s *
1028    audit_2021-05-17T00-00-00
888     audit_2021-05-18T00-00-00
1104    audit_2021-05-19T00-00-00
720     audit_2021-05-20T00-00-00
1204    audit_2021-05-21T00-00-00
656     audit_2021-05-22T00-00-00
680     audit_2021-05-23T00-00-00
724     audit_2021-05-24T00-00-00
984     audit_2021-05-25T00-00-00
880     audit_2021-05-26T00-00-00
716     audit_2021-05-27T00-00-00
488     audit_2021-05-28T00-00-00
1848    audit_2021-05-29T00-00-00
684     audit_2021-05-30T00-00-00
940     audit_2021-05-31T00-00-00
1836    files_2021-05-27T00-00-00
1144    files_2021-05-29T00-00-00
5100    files_2021-05-30T00-00-00
12476   files_2021-05-31T00-00-00
252     firewallandvpn_2021-05-29T00-00-00
612     firewallandvpn_2021-05-30T00-00-00
452     firewallandvpn_2021-05-31T00-00-00
10100   other_2021-05-16T00-00-00
3157056 other_2021-05-17T00-00-00
3259132 other_2021-05-18T00-00-00
3274084 other_2021-05-19T00-00-00
3377628 other_2021-05-20T00-00-00
3068380 other_2021-05-21T00-00-00
1002640 other_2021-05-22T00-00-00
806016  other_2021-05-23T00-00-00
3306924 other_2021-05-24T00-00-00
3681420 other_2021-05-25T00-00-00
3993888 other_2021-05-26T00-00-00
4442920 other_2021-05-27T00-00-00
150012  other_2021-05-28T00-00-00
296636  other_2021-05-29T00-00-00
1782444 other_2021-05-30T00-00-00
7185800 other_2021-05-31T00-00-00
39492   resources_2021-05-17T00-00-00
49812   resources_2021-05-18T00-00-00
44116   resources_2021-05-19T00-00-00
40788   resources_2021-05-20T00-00-00
38244   resources_2021-05-21T00-00-00
20096   resources_2021-05-22T00-00-00
11032   resources_2021-05-23T00-00-00
43084   resources_2021-05-24T00-00-00
42328   resources_2021-05-25T00-00-00
44000   resources_2021-05-26T00-00-00
51532   resources_2021-05-27T00-00-00
10632   resources_2021-05-29T00-00-00
115500  resources_2021-05-30T00-00-00
462532  resources_2021-05-31T00-00-00
468     smartevent_2021-05-29T00-00-00
1008    smartevent_2021-05-30T00-00-00
2288    smartevent_2021-05-31T00-00-00
12      template
 
 
 
Any clue as to what we've missed?
 
Regards
David Herselman