05-04-2020 05:08 AM
Hi,
I want to check the current log rotation for my FMC & how can i change it if required.
In other words i need to understand the period for which FMC is retaining logs for the logical devices.
Thanks
Solved! Go to Solution.
05-04-2020 07:13 AM
When we discuss "logs" in FMC we are generally speaking about what is called events in Firepower nomenclature. FMC does not have a time period after which events are deleted - rather it has a configurable set of event categories that are retained by total number of events, up to the platform maximum. you can see the number in your FMC under System > Configuration> Database as shown below.
The total number of events for all categories varies by platform and can be seen in the FMC product data sheet. They used to publish the number of events and now they just publish the overall database size. For an FMCv, the total is around 10 million events cumulative.
05-04-2020 06:14 AM
here is Logging config :
box will overwrite once the size reaches, instead you can offload to syslog and retain them as long as you want (depends on disk space available on syslog)
05-04-2020 06:52 AM
05-04-2020 07:13 AM
When we discuss "logs" in FMC we are generally speaking about what is called events in Firepower nomenclature. FMC does not have a time period after which events are deleted - rather it has a configurable set of event categories that are retained by total number of events, up to the platform maximum. you can see the number in your FMC under System > Configuration> Database as shown below.
The total number of events for all categories varies by platform and can be seen in the FMC product data sheet. They used to publish the number of events and now they just publish the overall database size. For an FMCv, the total is around 10 million events cumulative.
05-04-2020 08:34 AM
05-04-2020 09:24 AM
The limits configured in the FMC screen I showed are the governing ones regarding pruning. When the number of events in a given category exceeds the configured limit, FMC will begin deleting the oldest events in order to ingest newest ones.
The numbers in the data sheet regarding database size in GB are more for relative capacity comparison.
05-30-2024 11:42 PM
Hi marvin,
10 million events is events per second or total of any irresopective min/hours/days
05-31-2024 06:19 AM
Those are number or events.
There is a separate limit for events per second (EPS) - the limit is published in the product data sheet. The EPS over time can be seen in the FMC health monitor on newer releases.
05-31-2024 06:37 AM
05-31-2024 06:57 AM
The numbers in the database settings are events per particular type. The default values add up to almost the total number of events supported for the entire database (10 million).
An FMCv supports an ingest rate of approximately 5000 events per second.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide