<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The script is actually called in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031382#M1016179</link>
    <description>&lt;P&gt;The script is actually called "manage_pruning.pl". As a perl script, you can simply run it as-is from the cli. It is located and has options as follows:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;admin@sfvdc:/var/sf/bin$ pwd&lt;BR /&gt;/var/sf/bin&lt;BR /&gt;admin@sfvdc:/var/sf/bin$ sudo manage_pruning.pl&lt;BR /&gt;**************** Configuration Utility **************&lt;BR /&gt; 1 Status&lt;BR /&gt; 2 Prune configured items&lt;BR /&gt; 3 Purge Event database &amp;amp; (2)&lt;BR /&gt; 4 Print Status File&lt;BR /&gt; 0 Exit&lt;BR /&gt;**************************************************************&lt;BR /&gt;Enter choice: 0&lt;BR /&gt;Thank you&lt;BR /&gt;admin@sfvdc:/var/sf/bin$&lt;/PRE&gt;
&lt;P&gt;I don't know if or how one can customize the "configured items".&lt;/P&gt;
&lt;P&gt;Selecting option 2 results in the following (and the dashboard retains its application history and statistics):&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;**************************************************************&lt;BR /&gt;Enter choice: 2&lt;BR /&gt;Deleted file /var/tmp/pruning_status.msg&lt;BR /&gt;EOStore Pruner: DNSListObject.DataHandler 345 deleted&lt;BR /&gt;EOStore Pruner: Dashboard.DataHandler 5 deleted&lt;BR /&gt;EOStore Pruner: DashboardWidget.DataHandler 2 deleted&lt;BR /&gt;EOStore Pruner: IDSRule.DataHandler 16 deleted&lt;BR /&gt;EOStore Pruner: IDSRuleImport.DataHandler 5 deleted&lt;BR /&gt;EOStore Pruner: IPListObject.DataHandler 345 deleted&lt;BR /&gt;EOStore Pruner: IntrusionPolicy.DataHandler 3 deleted&lt;BR /&gt;EOStore Pruner: NetworkAnalysisPolicy.DataHandler 2 deleted&lt;BR /&gt;EOStore Pruner: SnortAttribConfig.DataHandler 4 deleted&lt;BR /&gt;EOStore Pruner: URLListObject.DataHandler 322 deleted&lt;BR /&gt;EOStore Pruner: VariableSet.DataHandler 1 deleted&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x136d7438) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x135e6460) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x137173c0) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x136d7438) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;**************** Configuration Utility **************&lt;BR /&gt; 1 Status&lt;BR /&gt; 2 Prune configured items&lt;BR /&gt; 3 Purge Event database &amp;amp; (2)&lt;BR /&gt; 4 Print Status File&lt;BR /&gt; 0 Exit&lt;BR /&gt;**************************************************************&lt;BR /&gt;Enter choice:&lt;/PRE&gt;</description>
    <pubDate>Fri, 30 Jun 2017 08:06:00 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-06-30T08:06:00Z</dc:date>
    <item>
      <title>Purging the database does not purge completely</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031377#M1016169</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are seeing a weird behaviour of information being retained on the FMC even after purging the database. E.g. We have purged all the connections &amp;amp; host information from the purge tab under system. I have also deleted all the logs from the context explorer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now in the context explorer the if the log view setting is set to past 1 hour we can see no data being loaded as expected. But if we set the setting to a 1 day or 1 week we can see the application data in the context explorer. But there are no logs pertaining to the applications if we drill into analysis of those applications.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similar behaviour is seen on the summary dashboard with regards to the log view setting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this a bug or is there a command on the FMC to purge the historical data completely ?&lt;/P&gt;
&lt;P&gt;I could not find any reference to this behaviour in the documentation. Any help on the same would be great.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031377#M1016169</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2019-03-12T13:20:38Z</dc:date>
    </item>
    <item>
      <title>hi team, </title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031378#M1016171</link>
      <description>&lt;P&gt;hi team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any take on this one. Tried purging the database multiple times from the FMC but the application data from the network analysis still persists. We are not able to troubleshoot the statistics of application data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 20:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031378#M1016171</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2017-03-29T20:55:01Z</dc:date>
    </item>
    <item>
      <title>I have the same problem. Ever</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031379#M1016173</link>
      <description>&lt;P&gt;I have the same problem. Ever come up with a solution?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 20:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031379#M1016173</guid>
      <dc:creator>Mark Alley</dc:creator>
      <dc:date>2017-04-25T20:22:48Z</dc:date>
    </item>
    <item>
      <title>Hi Mark, </title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031380#M1016175</link>
      <description>&lt;P&gt;Hi Mark,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I tried the procedure multiple times and only find that the logs are purged from the context explorer and not from the dashboard. the statistics of the applications remain as it is.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is really bad and there is no documentation around it and neither any notes about this behaviour nor any help on the community around it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think there is a Cli command in the linux shell to purge it completely but I guess only CiscoTac is aware of it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 09:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031380#M1016175</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2017-05-03T09:36:45Z</dc:date>
    </item>
    <item>
      <title>I think there is a Cli perl</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031381#M1016177</link>
      <description>&lt;P&gt;I think there is a Cli perl script called managed_pruning but I don't know the syntax of running this script on the fmc. Also there is a bug associated with it even in 6.2.0 with bug id&amp;nbsp;CSCvc51459&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure if this issue is resolved yet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 18:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031381#M1016177</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2017-06-28T18:57:14Z</dc:date>
    </item>
    <item>
      <title>The script is actually called</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031382#M1016179</link>
      <description>&lt;P&gt;The script is actually called "manage_pruning.pl". As a perl script, you can simply run it as-is from the cli. It is located and has options as follows:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;admin@sfvdc:/var/sf/bin$ pwd&lt;BR /&gt;/var/sf/bin&lt;BR /&gt;admin@sfvdc:/var/sf/bin$ sudo manage_pruning.pl&lt;BR /&gt;**************** Configuration Utility **************&lt;BR /&gt; 1 Status&lt;BR /&gt; 2 Prune configured items&lt;BR /&gt; 3 Purge Event database &amp;amp; (2)&lt;BR /&gt; 4 Print Status File&lt;BR /&gt; 0 Exit&lt;BR /&gt;**************************************************************&lt;BR /&gt;Enter choice: 0&lt;BR /&gt;Thank you&lt;BR /&gt;admin@sfvdc:/var/sf/bin$&lt;/PRE&gt;
&lt;P&gt;I don't know if or how one can customize the "configured items".&lt;/P&gt;
&lt;P&gt;Selecting option 2 results in the following (and the dashboard retains its application history and statistics):&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;**************************************************************&lt;BR /&gt;Enter choice: 2&lt;BR /&gt;Deleted file /var/tmp/pruning_status.msg&lt;BR /&gt;EOStore Pruner: DNSListObject.DataHandler 345 deleted&lt;BR /&gt;EOStore Pruner: Dashboard.DataHandler 5 deleted&lt;BR /&gt;EOStore Pruner: DashboardWidget.DataHandler 2 deleted&lt;BR /&gt;EOStore Pruner: IDSRule.DataHandler 16 deleted&lt;BR /&gt;EOStore Pruner: IDSRuleImport.DataHandler 5 deleted&lt;BR /&gt;EOStore Pruner: IPListObject.DataHandler 345 deleted&lt;BR /&gt;EOStore Pruner: IntrusionPolicy.DataHandler 3 deleted&lt;BR /&gt;EOStore Pruner: NetworkAnalysisPolicy.DataHandler 2 deleted&lt;BR /&gt;EOStore Pruner: SnortAttribConfig.DataHandler 4 deleted&lt;BR /&gt;EOStore Pruner: URLListObject.DataHandler 322 deleted&lt;BR /&gt;EOStore Pruner: VariableSet.DataHandler 1 deleted&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x136d7438) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x135e6460) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x137173c0) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Syntax error near 'limit' on line 4 (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 810.&lt;BR /&gt;ERROR: Unable to prepare HASH(0x136d7438) at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm line 812.&lt;BR /&gt;**************** Configuration Utility **************&lt;BR /&gt; 1 Status&lt;BR /&gt; 2 Prune configured items&lt;BR /&gt; 3 Purge Event database &amp;amp; (2)&lt;BR /&gt; 4 Print Status File&lt;BR /&gt; 0 Exit&lt;BR /&gt;**************************************************************&lt;BR /&gt;Enter choice:&lt;/PRE&gt;</description>
      <pubDate>Fri, 30 Jun 2017 08:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031382#M1016179</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-30T08:06:00Z</dc:date>
    </item>
    <item>
      <title>Thanks a lot for this Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031383#M1016181</link>
      <description>&lt;P&gt;Thanks a lot for this Marvin,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see there are issues when running this script.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Unable to execute SELECT count(*) as count FROM SRU_import_log&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;() at /usr/local/sf/lib/perl/5.10.1/SF/Pruning/ProcessDB.pm&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I didn't get the other errors you got when running the script.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I tried both the options &amp;nbsp;2 &amp;amp; 3 &amp;amp; yes you are right. the application &amp;amp; connection statistics remain as it is in the dashboard.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;It's clear there is a bug with the purging of the database. If the dashboard still shows statistics it means there are recorded somewhere in the database.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;My experience with the FMC is very bad too buggy &amp;amp; clunky software.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2017 03:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031383#M1016181</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2017-07-01T03:38:00Z</dc:date>
    </item>
    <item>
      <title>I suspect the script has not</title>
      <link>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031384#M1016183</link>
      <description>&lt;P&gt;I suspect the script has not been updated as the database schema has been modified over several releases.&lt;/P&gt;
&lt;P&gt;Which errors you get probably depends on how many versions you are past the one for which the script was created.&lt;/P&gt;
&lt;P&gt;I agree the software is in need of a makeover. Under the covers there is a LOT of legacy code. The new FTD bits haven't helped as there are now pieces of the old Cisco Security Manager (CSM) embedded into FMC.&lt;/P&gt;
&lt;P&gt;I keep hoping some of the Meraki (or Viptela) approach to UI design and functionality can be incorporated into the Cisco secuirty product line. We shall see....&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2017 13:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/purging-the-database-does-not-purge-completely/m-p/3031384#M1016183</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-01T13:13:23Z</dc:date>
    </item>
  </channel>
</rss>

