Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marko_Grmek
Participant

how to delete a log partition coming from certain firewall to SMS

Hello experts,

 

I have many firewalls connected to  SMS which manages all firewalls.

All the logs of the Gateways are being sent to and stored on SMS.

Can someone write a way how to see specific log partitions coming from each firewall?

it shall be in  /var/log/opt/.... but I can only find all partitions mixed together

Let´s say I want to delete all logs coming from one specific gateway. Is it possible?

 

Thank you,

 

Marko

 

 

 

8 Replies
the_rock
Legend
Legend

Thats very good question actually! I checked my lab mgmt server and if you navigate to $FWDIR/log dir and then do command ls -lh *.log, you get bunch of files, BUT, none of them have gw name, just date and then .log at the end, as per below.

Andy

-rw-rw---- 1 admin root 20M Aug 29 00:00 2023-08-29_000000.log
-rw-rw---- 1 admin root 33M Aug 30 00:00 2023-08-30_000000.log
-rw-rw---- 1 admin root 25M Aug 31 00:00 2023-08-31_000000.log
-rw-rw---- 1 admin root 36M Sep 1 00:00 2023-09-01_000000.log
-rw-rw---- 1 admin root 28M Sep 2 00:00 2023-09-02_000000.log
-rw-rw---- 1 admin root 19M Sep 3 00:00 2023-09-03_000000.log
-rw-rw---- 1 admin root 19M Sep 4 00:00 2023-09-04_000000.log
-rw-rw---- 1 admin root 21M Sep 5 00:00 2023-09-05_000000.log
-rw-rw---- 1 admin root 23M Sep 6 00:00 2023-09-06_000000.log
-rw-rw---- 1 admin root 33M Sep 7 00:00 2023-09-07_000000.log
-rw-rw---- 1 admin root 26M Sep 8 00:00 2023-09-08_000000.log
-rw-rw---- 1 admin root 7.7M Sep 8 09:26 fw.log

0 Kudos
Marko_Grmek
Participant

So I guess it is not possible to see specific partitions?

Which logs shall I delete not to delete any system relevant logs ?

All logs older than 1 year? Or maybe logs from different GAIA Versions?

What is recommended?

 

thank you,

 

Marko

 

0 Kudos
the_rock
Legend
Legend

Really depends on the business/audit purposes. If you dont need logs older than 1 year, I think they can safely be deleted.

Andy

0 Kudos
Marko_Grmek
Participant

Thank you rock :),

 

I was thinking there may be preferred way to delete files above certain size with something like:

find /var/log -type f -size +1000000 -exec ls -lh {} \; 2> /dev/null | awk '{ print $NF ": " $5 }' | sort -nk 2

 

 

0 Kudos
the_rock
Legend
Legend

You can, there are few ways : - )

0 Kudos
scenarist
Contributor

Hello guys,

is there a way to connect via some sftp or ftp client (like is winSCP) to mgmt server (which is in my case log server) and delete logs or there is only one way through command line and expert mode. I asked that because I am not the best with commands in expert mode:)

0 Kudos
emmap
Employee
Employee

You can connect via WinSCP but you'll have to log in with a user configured to use the /bin/bash shell. 

scenarist
Contributor

Oh. Yes! Thank you very much...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events