I upgraded management to R80.10 on December 19, 2017. My new log server now is 93% full and I realize now after reading the Logging and Monitoring R80.10 Administration Guide, it is mostly useless. I am trying to be objective here and not overly critical but there is only one sentence in this admin guide about managing logs:
"SmartEvent and Log Server use an optimization algorithm to manage disk space and other system resources. When the Logs and Events database becomes too large, the oldest logs and events are automatically deleted to save space."
No, deleting is not managing. I have been copying off log files since R61 but now the logs are in database format and not flat files so it would be very helpful if I could learn how to get it done. It is very likely this will only need to be done once - very soon I will have syslog running to a 5TB log server.
I like the idea about getting logs from Endpoint Management Server R77.30.03 into the R80.10 platform to unify all threat management.
Any help will be appreciated, best regards,