This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Log Disk

How do I eliminate getting my Log Disk to 85-93% everyday?
here's my Local Log Settings

Automatic log file deletion
deletes logs after 20 days

Threshold One
When usage reaches 50%
delete oldest logs file

Threshold Two
When usage reaches 85%
delete oldest logs file

Threshold Three
When usage reaches 95%
delete oldest logs file

Do I configured my Log settings correctly.


This thread was automatically locked due to age.
  • Have you looked at Logging >> View Log files and checked "Today's log files" and also browsed through the archived logs to see which log files are large? 

    If the log files are growing quickly I'm sure at least one of the logs will be quite large each day, once you find the logfile(s) that is taking up the space you can then start to troubleshoot the issue by finding out what is being written to the logfile.
  • It shows the Packet Filter eats my Local Logs space arounds 6.2 GB the rest its a matter or Kb only.
  • If your packet filter logs are that large, do you have rules set to log all your traffic?  If so, that's where the volume is coming from.  There's no need to log every passed packet through the system.  If you are seeing that many drops, you may need to dig into the logs to see the root cause of the excess bad traffic.  If there's broadcast or multicast traffic that is generated by a system on your network, you may want to add a drop rule w/ no logging for those specific items so they aren't logged on your firewalls' internal interface.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Hello,

    See the attached file how do I config my Packet Filter Rules.

    FYR.......QCIT-NINE and PRoxy2 are proxies of internal network.
    VIPNet 8.95.0 are VIP network
    WirelessNet 8.96.0 are VIP wireless network
  • None of those are logged, so, as Bruce said, "If you are seeing that many drops, you may need to dig into the logs to see the root cause of the excess bad traffic."
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Can you help me how to dig my packet filter?
    Im sorry to tell this Im not linux guru to play the inner portion of astaro.I knew that the software behind astaro is hardened linux.
    My point is can you provide me the commands in order to execute what you want me to do.Thanks
  • No Linux required:

    'Logging >> View LogFiles'
    'Today's Log Files' tab
    'Packet Filter' (View)
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Im back in regards to Local Logs. 
    Somebody could help me to eliminate my Local Logs fast growing as of now 65% are already utilized within a month? 
    I compared same model of astaro to one of our clients which I deployed 4 months ago yet the logs is all about 2-3%. 
    I cant figure out what the cause of this problem mypremiercreditcard

  • What are the five largest logs near the end of the day?  Names and sizes, please.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA