The Security Engine stores audit data and old logs temporarily until the data is sent to the Log Server.
Below steps help you to set the storage option on the Security Engine for deleting the audit data and old logs which was tested on the evaluated
configuration.Note: Before attempting the steps below, complete the steps for creating an element for the Security Engine as explained in section,
Create an element for the Security Engine.
Steps
-
Set the Log Spooling Policy option to Stop Traffic.
When the Log Spooling Policy option is set to Stop Traffic, the Security Engine goes offline when the local storage
space is full. This can happen when the Log Server is not available or when the Log Server storage space is becoming full and the Log Server stops the log reception.
-
To check what the Log Spooling Policy option is set to for an Security Engine, in the Engine
Editor, browse to Advanced Settings > Log handling.