12-21-2011 06:56 AM
Hello,
Is there anyway to backup and restore logs and quarantine to another ironport c170?Thanks in advance.
Alexandre
Solved! Go to Solution.
12-23-2011 04:07 AM
Hello Alexandre,
logs can easily be downloaded via FTP or SCP, there is a folder per logs subscription, i.e.
/mail_logs
/system_logs
/error_logs
Each folder contains multiple logs, thos e are with extention .s are the ones that have rolled over, while .c and .current are the ones currently written to. I would not recommend to upload them to another appliance, as this may cause problems or at least confusion. Quarantines cannot be backed up, that functionality is limited to SMAs (M-series).
Hope that helps,
Andreas
12-23-2011 04:07 AM
Hello Alexandre,
logs can easily be downloaded via FTP or SCP, there is a folder per logs subscription, i.e.
/mail_logs
/system_logs
/error_logs
Each folder contains multiple logs, thos e are with extention .s are the ones that have rolled over, while .c and .current are the ones currently written to. I would not recommend to upload them to another appliance, as this may cause problems or at least confusion. Quarantines cannot be backed up, that functionality is limited to SMAs (M-series).
Hope that helps,
Andreas
12-29-2011 12:51 AM
Hi Andreas,
Thanks for your prompt response.
Moreoever, how can exploit this logs (e.g : /mail_logs, /system_logs, /error_logs) in the best and most efficient way ? (eq: Cisco tools...)
Best regards,
Alexandre
12-30-2011 01:14 AM
Hello Alexandre,
the logs are normal text files that you can open with any text editor, or grep as usual from any command line. There is also the findevent command available for download:
https://supportforums.cisco.com/docs/DOC-9075
On the same link, there is also a tool called spamtowho.exe, which you can use for statistics, reporting, etc. on Cisco IronPort mail logs.
Hope that helps,
Andreas
09-26-2017 02:49 AM
Is there any procedure to backup the logs?
09-26-2017 03:55 AM
Hi,
You can use FTP or SCP to access the appliance and download the logs to your system.
You can also navigate to System Administration -> Log Subscriptions -> Click on a log to modify -> Retrieval Method -> To push the logs to a different server.
- Libin V
09-27-2017 02:46 AM
Thank you Libin. Do you have an idea how can we access the root of WSA? because we're still getting the logging disk high utilization.
09-27-2017 02:55 AM
I do not think root access is available for end customers, at least that is the case for ESA.
I would recommend opening a case with TAC to get that reviewed.
It would be best to have an engineer check if the high disk usage is due to a defect before you decide on deleting logs.
- Libin V
09-27-2017 04:02 AM
09-27-2017 08:01 AM
Thank you Ken for the information. Right now our logging disk is 97%, and we would like to know what causes the high utilization of logging disk?
09-27-2017 08:14 AM
09-27-2017 04:42 PM
Thanks Ken,
How can we tweak the settings?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide