<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE local logs purge settings in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3758948#M527774</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any solution we have to this at the end, let me guess NO!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running ISE 2.4 in cluster and Primary getting disconnected because of logs are full.&lt;/P&gt;
&lt;P&gt;What other ways we have to delete logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;B&lt;/P&gt;</description>
    <pubDate>Thu, 06 Dec 2018 13:37:11 GMT</pubDate>
    <dc:creator>Beacon Bits</dc:creator>
    <dc:date>2018-12-06T13:37:11Z</dc:date>
    <item>
      <title>ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491434#M527766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I would like to clarify with a behavior related to the local logs purge settings, as from following link:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01010.html#task_45D4F2EFA1D9486093DFD2F3B44AC165"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01010.html#task_45D4F2EFA1D9486093DFD2F3B44AC165&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We are using the “local Log Storage Period” and “Delete Logs Now” settings, but the logs are not removed. Based on several trials into the GUI, we are observing that the logs are deleted &lt;STRONG&gt;only if the storage is full&lt;/STRONG&gt;. Otherwise the logs are not deleted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Based on that, the question is: Using the above local logs settings, &lt;STRONG&gt;is it true that local log is not removed until the log space reach the threshold?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;From the admin guide I understand that when you set a purge time, or especially if you use the setting “Delete Logs Now”, it should delete the logs, independently from the storage space.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;The concern come from the need to delete all the Guest information from ISE every X days. We know this is possible thanks to the "&lt;/SPAN&gt;&lt;SPAN class="s3"&gt;&lt;STRONG&gt;Schedule purge of expired guest accounts”, &lt;/STRONG&gt;b&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;ut in the following admin guide (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01110.html#ID1242"&gt;&lt;SPAN class="s4"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01110.html#ID1242&lt;/SPAN&gt;&lt;/A&gt;) is well explained that "&lt;/SPAN&gt;&lt;SPAN class="s3"&gt;When expired guest accounts are purged, the associated endpoints and &lt;STRONG&gt;reporting and&lt;/STRONG&gt; &lt;STRONG&gt;logging information are retained”.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;This is the reason why we are looking for the local logs purge settings, because of the need to automatically delete ALL the Guest info in ISE, also the reporting and logging Guest information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Thanks in advance for your support.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2017 16:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491434#M527766</guid>
      <dc:creator>fepetruz</dc:creator>
      <dc:date>2017-08-09T16:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491435#M527767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am researching but your initial findings sound correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The disk would be full before cleaning it out, this way we are able to keep the max amount of logs as possible before customers have to think about an external system to keep more of the logs for their retention policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2017 17:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491435#M527767</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-09T17:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491436#M527768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;keep in mind &lt;/P&gt;&lt;P class="text" style="font-family: Helvetica; padding: 7px 0 0; color: #000000;"&gt;&lt;SPAN style="font-size: 16px;"&gt;localStore logs are local copies of events that sending over to M&amp;amp;T. They are good for debugging.&lt;/SPAN&gt;&lt;SPAN class="message_id"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="text" style="font-family: Helvetica; padding: 7px 0 0; color: #000000;"&gt;&lt;SPAN style="font-size: 16px;"&gt;usually we keep 7 days only.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2017 17:56:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491436#M527768</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-08-09T17:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491437#M527769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you confirm that even using the "Delete Logs Now" option for example, it doesn't delete the logs in that moment (now), but we have to wait anyway that the memory will be full? &lt;/P&gt;&lt;P&gt;It seems weird to me because in this way these settings (also the "&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;local Log Storage Period") &lt;/SPAN&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;are not useful anymore, but trying to play with it seems to be like that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Could I ask then, is there any alternative way to automatically delete the logs without waiting that the memory become full?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Thanks again!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 07:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491437#M527769</guid>
      <dc:creator>fepetruz</dc:creator>
      <dc:date>2017-08-10T07:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491438#M527770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See my response to &lt;A _jive_internal="true" href="https://community.cisco.com/thread/84618"&gt;Guest account data privacy concern&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 12:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491438#M527770</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-10T12:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491439#M527771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frederico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you ever get a satisfactory answer to your question?&amp;nbsp; I am on the same page as you.&amp;nbsp; My nodes are becoming logging graveyards and I cannot purge these things via the GUI. I was generous enough to create my PAN nodes with 1.2TB of data (stupid, right ?) and now it seems to cause ISE to retain my logs forever since I have so much disk space.&lt;/P&gt;&lt;P&gt;The problem is that logs are contained inside config backups (now that is really stupid). And every config backup I make contains months worth of logs that nobody needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my mind, a "purge all data now" means exactly that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I rebuild my ISE nodes for ISE 2.4 "upgrade" then I will make them 200GB - saves resources too.&lt;/P&gt;&lt;P&gt;I don't need GB's of Java heap errors logged for any reason.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 23:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491439#M527771</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-03-28T23:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491440#M527772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have some log-rotation bugs and most of them have been resolved in patch releases, such as CSCva95303.&lt;/P&gt;&lt;P&gt;Regarding the CFG backups with logs, it's a known issue -- CSCuq59764.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned in other comments, the web UI options are for operational data and iseLocalStore log files but not for debug log files. Please open a Cisco TAC case so TAC may help purging the debug log files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 00:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491440#M527772</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-29T00:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491441#M527773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regarding known issue CSCuq59764, this has been around since ISE 1.2 - what are the chances of getting this sorted?&amp;nbsp; Is the intention to create a Config Backup that does not contain any logs?&amp;nbsp; That would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Arne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 04:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3491441#M527773</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-04-03T04:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3758948#M527774</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any solution we have to this at the end, let me guess NO!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running ISE 2.4 in cluster and Primary getting disconnected because of logs are full.&lt;/P&gt;
&lt;P&gt;What other ways we have to delete logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;B&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 13:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3758948#M527774</guid>
      <dc:creator>Beacon Bits</dc:creator>
      <dc:date>2018-12-06T13:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE local logs purge settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3758956#M527775</link>
      <description>I would suggest you start a new thread with details such as show disks output from the effected node. 2.4 have no known disk full issues as such AFAIK.</description>
      <pubDate>Thu, 06 Dec 2018 13:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-local-logs-purge-settings/m-p/3758956#M527775</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-06T13:43:51Z</dc:date>
    </item>
  </channel>
</rss>

