- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi
just reviewing disc management on a MDS R80.40.
What is the best practice to do housekeeping in terms of fw logs to avoid disk full scenarios.
e.g. If you want to keep log files / audit log files for a period of time. Ideally adjustable per domain(CMA).
Logs/Advanced settings is only available for gateways, correct?
Or is creating cleanup scripts with cron jobs the way to go.
Regards
You need to take care about log files (.fwlog files), but ALSO indexed logs.
In case of MDS, you dont have possibility to set treshold in SmartConsole like you want for specific domain. You need script to delete logs for specific domain ( /var/log/mds_logs/<domain_name>/logs/ ).
In case of index files, see
How to configure log/Indexes maintenance policy for Global SmartEvent and MDS
Yes, thanks, this is more related to gateways.
Couldn't see any disc quota stuff for management.
Regards
Hi
The request was to keep logs for a certain amount of time. How does this setting differentiate certain domains and time?
Something like [] delete logs older than 90 days / domain1...
Thanks
Regards
You need to take care about log files (.fwlog files), but ALSO indexed logs.
In case of MDS, you dont have possibility to set treshold in SmartConsole like you want for specific domain. You need script to delete logs for specific domain ( /var/log/mds_logs/<domain_name>/logs/ ).
In case of index files, see
How to configure log/Indexes maintenance policy for Global SmartEvent and MDS
This sk is the solution i think - it explain all log and index size settings for MDS.
hi,
ok, this helps (sk117317).
sk123532 log_keep_on_days and log_keep_days_value are no longer supported.
The disc size approach does not help due to the fact it is shared across all domains with different amount of logs.
I will try to create scripts.
Thanks a lot
Regards
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY