Security

last person joined: yesterday 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  Security director - set max logging history

    Posted 08-16-2019 07:15
    Hi,

    I have a separate logging node in my security director installation. How can I set the logging to a max history so it doesn’t fill up?

    I just don’t want the logging node to fill up with space etc

    Ideally I would set this to 6 months and everything else just gets deleted after this date?

    Thanks


  • 2.  RE: Security director - set max logging history

     
    Posted 08-16-2019 07:29
    By default it keeps 45 days logs OR till 80% of disk space is available.

    Regards,
    Pravin


  • 3.  RE: Security director - set max logging history

    Posted 08-16-2019 07:43
    That’s good - thanks

    Is there a setting I can change to set this to 6 months instead?


  • 4.  RE: Security director - set max logging history
    Best Answer

     
    Posted 08-16-2019 07:58
    There is a file in the file system where you can change it, i do not have that handy now.

    Check "crontab -l" in log collector then you will find a script and in that script, you will get that file where 45 days is mentioned.

    Regards,
    Pravin


  • 5.  RE: Security director - set max logging history

     
    Posted 10-11-2019 00:37

    Just to give the exact location of the script:

     

    This script will roll over the old logs and it is in cronjob: /opt/jIngest/watcher/elasticsearchDiskRollover.py

     

    Number of days to keep the logs are configured in:  /opt/jIngest/watcher/elasticDiskRollover.cfg

     

    Daily old log rollover logs can be seen in:/var/log/diskrollover.log

     

    By default, 500GB gets assigned to Log collector node so once it reaches 80% i.e. 400G, LC starts purging old logs.

    400G is configured in /opt/jIngest/watcher/elasticsearchDiskRollover.py script ( LC automatically calculate 80% of total disk space assigned so the user need not require to edit it) 

     

    -PL



  • 6.  RE: Security director - set max logging history

    Posted 10-11-2019 23:30
    I recently had a problem where the logs filled up and didn’t rotate; it stopped security directors web page from loading properly.

    I used this fix to resolve - https://kb.juniper.net/InfoCenter/index?page=content&id=KB33248&actp=METADATA