Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
S_E_
Advisor
Jump to solution

disc management

Hi

just reviewing disc management on a MDS R80.40.
What is the best practice to do housekeeping in terms of fw logs to avoid disk full scenarios.
e.g. If you want to keep log files / audit log files for a period of time. Ideally adjustable per domain(CMA).

Logs/Advanced settings is only available for gateways, correct?

Or is creating cleanup scripts with cron jobs the way to go.

Regards

0 Kudos
1 Solution

Accepted Solutions
JozkoMrkvicka
Mentor
Mentor

You need to take care about log files (.fwlog files), but ALSO indexed logs.

In case of MDS, you dont have possibility to set treshold in SmartConsole like you want for specific domain. You need script to delete logs for specific domain ( /var/log/mds_logs/<domain_name>/logs/ ).

In case of index files, see 
How to configure log/Indexes maintenance policy for Global SmartEvent and MDS

Kind regards,
Jozko Mrkvicka

View solution in original post

7 Replies
G_W_Albrecht
Legend Legend
Legend

See  sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Ser...

 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
S_E_
Advisor

Yes, thanks, this is more related to gateways.

Couldn't see any disc quota stuff for management.

Regards

0 Kudos
G_W_Albrecht
Legend Legend
Legend

logsms.png

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
S_E_
Advisor

Hi

The request was to keep logs for a certain amount of time. How does this setting differentiate certain domains and time?

Something like [] delete logs older than 90 days / domain1...

Thanks

Regards

0 Kudos
JozkoMrkvicka
Mentor
Mentor

You need to take care about log files (.fwlog files), but ALSO indexed logs.

In case of MDS, you dont have possibility to set treshold in SmartConsole like you want for specific domain. You need script to delete logs for specific domain ( /var/log/mds_logs/<domain_name>/logs/ ).

In case of index files, see 
How to configure log/Indexes maintenance policy for Global SmartEvent and MDS

Kind regards,
Jozko Mrkvicka
G_W_Albrecht
Legend Legend
Legend

This sk is the solution i think - it explain all log and index size settings for MDS.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
S_E_
Advisor

hi,

ok, this helps (sk117317).

sk123532 log_keep_on_days and log_keep_days_value are no longer supported.

The disc size approach does not help due to the fact it is shared across all domains with different amount of logs.

I will try to create scripts.

Thanks a lot

Regards

 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events