cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1446
Views
5
Helpful
3
Replies

Firepower Management Centre - Sourcefire Snort directory size (200GB+)!

magurwara
Level 1
Level 1

Hi,

Currently facing a disk utilization issue on FMC1500 at a client.  Clearing old updates, patches, and log files, recovered about 10GB but the /var partition is full again causing FMC GUI to stop working.

 

Checking disk usage, the "sfsnort" directory is 200GB+.  Total /var partition is 280GB.

 

Any ideas how to reduce the size of this directory?


Thanks,

 

mag

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

I always recommend a TAC case when modifying the directories within an FMC. It is very easy to make the system have an unrecoverable error if you do something wrong.

Resolved!

 

Opened a Cisco TAC case as suggested by @Marvin Rhoads 

TAC engineer removed a bunch of files, name containing "packet_log",  from the sfsnort directory.

Brought down disk utilization very significantly and all is well now.

Apparently these were very old files.

 

Thanks for sharing your solution.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: