2018-10-04 10:55 AM
Hello
Im noticing that the concentrator is losing data....since yesterday we lost 3 days of logs: We could query since 19 of September and today we can only see data since 22 of September. I need to stop that....is that possible?
How can i put the logs that are in the log decoder because the log as data since 9 September. Only with the suggestion from Dave Glover? https://community.rsa.com/message/917738? How can i set da bigger data retention?
2018-10-04 04:57 PM
Thanks for the help John.
2018-10-04 05:00 PM
You're very welcome sorry we couldn't easily fix your issue here.
2018-10-04 05:12 PM
No problem...
It was a big help.
PS: Its already done w/ support.... We created another 150GB for the concentrator
2018-10-08 03:50 AM
Does any of you knows if theres been some changes in version 11.2, regarding maintaining the logs?
2018-10-08 10:12 AM
Hello John,
Today i had a bad contact with RSA NW. We lost more data....and we can only see events/logs from 02 October. It means that we are losing data day by day....i already contacted support and they didn't reply. Can you give me some help?
We need to deliver a report to one of our clients regarding September and we can't
2018-10-08 12:33 PM
Hi Renato,
We are already discussing this on the Case that we have, But I would like to emphasize on something - According to your df -h output from the Concentrator;
/dev/mapper/centos-root 551G 364G 187G 67% /
devtmpfs 5.7G 0 5.7G 0% /dev
tmpfs 5.7G 12K 5.7G 1% /dev/shm
tmpfs 5.7G 593M 5.1G 11% /run
tmpfs 5.7G 0 5.7G 0% /sys/fs/cgroup
/dev/mapper/centos-home 137G 33M 137G 1% /home
/dev/vda1 497M 184M 314M 37% /boot
tmpfs 1.2G 0 1.2G 0% /run/user/0
You may have all your metadb, indexdb, sessiondb partitions located in the root partition- /dev/mapper/centos-root.
We specify these metadb,sessiondb,packetdb,indexdb as Core Databases or Datastores
If you refer to the Virtual Host Deployment/Installation Guide for NW 11.2 - Virtual Host Installation Guide for Version 11.2
Page 19 - "Step 3. Configure Databases to Accommodate NetWitness Platform"
When you install a Decoder or a Concentrator all of your Core databases are stored in one partition. As per the guide - "By default, the database size is set to 95% of the size of file system on which the database resides".
The customer should specify and Review Optimal Datastore Space Configuration according to their environment as specified in Task 2.
That step is essential to maintain proper storage requirements for the appliances.
The values could be set in the explore view of Decoders and concentrators. Ideally, the Datastores should be in different (separate) partitions, However we can check which sizes have been set in explore view for meta, session and index dbs.
Thanks and Best Regards,
Suneth Jayarathne
2018-10-10 01:07 PM
One more thing that potentially may shorten a log retention on a concentrator is core.* file(s) being saved in the metdb directory if the concentrator had crashed at some point.