11-20-2020 02:51 AM
Hi there,
we are not allowed to store Logs longer than 90 days on our systems.
How do you set this up?
All our ESAs send their logs to our SMA, which is then used by our support to find details to mail sendings. All i can find regarding this issue are threads from 2013 which state that this feature is not implemented yet and you should just setup the available space so that it kind of fits. I hope that now, 7 years later i can set up a max age for log files.
Cheers
11-20-2020 03:28 AM
To clarify, logs are not pushed from ESA's to SMA.
It's reporting, tracking and quarantines that are centralised.
For the centralised features there is no time based rollover at the moment.
The enhancements are yet to be prioritised or added to a road map from what I can see.
You may want to reach out to your Accounts team to get this prioritised.
Regards,
Libin
11-20-2020 06:47 AM
We had a similar issue and the initial feature request to limit data in ESA/SMA cames form us.
Our workaround currently is we ingest all data into Splunk and have a 90 days retention defined for the email data.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide