04-01-2025 08:01 AM
We recently upgraded from FMCv7.4.2.1 to 7.6.0.113 and ran into a logging issue (FTD remains at 7.4.2.1). This was after FMCv hung on reboot referencing a Perl script that hung on a database operation. Of course TAC was on the call, we had planned the upgrade proactively with them. After a hour, TAC recommended rebooting which completed the upgrade but now logging is hosed. We typically have about six months of logs but now no matter the query specification, we can only retrieve about six hours of logs. TAC does not have a fix other than to restore back to 7.4.2.1.
We do not have redundant FMCv, but we could if it would help us recover from this scenario, something like this: build a new FMCv independently with a fresh database, restore the ACP and other settings separately, bring into HA, etc? Trying to figure out if this is the best solution. Please advise if you know the details.
04-08-2025 08:34 AM
Just to confirm: Is your issue/goal to restore historical data/events or is the FMC simply not retaining data/events beyond 6 hours?
Thank you for rating helpful posts!
04-08-2025 08:53 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide