Symantec 10521146 Administration Guide - Page 249

Archiving log files, Setting Size to Trigger Rotation

Page 249 highlights

Managing log files 249 Configuring automatic archiving 6 In Apply Changes To, select the node to which to apply the parameter. 7 Click OK to save the changes to this node and close. Note: Restart Symantec Network Security for changes to this parameter to take effect. Note: For information about how to manage logs manually, see "About the Knowledge Base" on page 22. Archiving log files To conserve disk space and ensure optimal performance, the Network Security incident and event logs should be archived and compressed periodically. SuperUsers and Administrators can archive the logs based on file size, time, or both. To conserve space on the node, you can use Secure Copy Protocol (SCP) to move the archived logs to another host. Symantec Network Security automatically performs log archiving based on log size. SuperUsers and Administrators can control log archiving by editing the Size to Trigger Rotation parameter. Alternatively, you can configure Symantec Network Security to perform time-based log archiving. In either case, you must configure the Compression On/Off Switch if log compression is desired. Caution: Tune your log file archiving based on the amount of attack traffic your site experiences. If the log directory becomes full, logging and reporting of incident and event data to the Network Security console will be suspended. Monitor your disk space to ensure that there continues to be sufficient space for the logs. Use the following Log and Database Parameters to establish a static system that shrinks and grows without intervention: ■ Setting Size to Trigger Rotation ■ Setting Limit Size for Archive Directory ■ Setting Limit Size for Traffic Record Directory Setting Size to Trigger Rotation Size to Trigger Rotation determines the size at which the logs and database files are archived. Symantec Network Security checks the log and database sizes periodically, and archives them when they exceed this size.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

249
Managing log files
Configuring automatic archiving
6
In
Apply Changes To
, select the node to which to apply the parameter.
7
Click
OK
to save the changes to this node and close.
Note:
Restart Symantec Network Security for changes to this parameter to take
effect.
Note:
For information about how to manage logs manually, see
²About the
Knowledge Base³
on page 22.
Archiving log files
To conserve disk space and ensure optimal performance, the Network Security
incident and event logs should be archived and compressed periodically.
SuperUsers and Administrators can archive the logs based on file size, time, or
both. To conserve space on the node, you can use Secure Copy Protocol (SCP) to
move the archived logs to another host.
Symantec Network Security automatically performs log archiving based on log
size. SuperUsers and Administrators can control log archiving by editing the
Size to Trigger Rotation parameter. Alternatively, you can configure Symantec
Network Security to perform time-based log archiving. In either case, you must
configure the Compression On/Off Switch if log compression is desired.
Caution:
Tune your log file archiving based on the amount of attack traffic your
site experiences. If the log directory becomes full, logging and reporting of
incident and event data to the Network Security console will be suspended.
Monitor your disk space to ensure that there continues to be sufficient space for
the logs.
Use the following Log and Database Parameters to establish a static system that
shrinks and grows without intervention:
Setting Size to Trigger Rotation
Setting Limit Size for Archive Directory
Setting Limit Size for Traffic Record Directory
Setting Size to Trigger Rotation
Size to Trigger Rotation
determines the size at which the logs and database files
are archived. Symantec Network Security checks the log and database sizes
periodically, and archives them when they exceed this size.