Deleting log and audit data

The Security Engine stores log data temporarily until the data is sent to the Log Server. The Log Server is responsible for sending log data to the configured external audit server.

The Management Server and Log Server store audit and log data locally, then send the data to an external audit server. Locally stored audit and log data cannot be modified. Locally-stored data is not deleted automatically. Administrator can manage locally stored log and audit retention period by configuring log deletion tasks as instructed in the Managing log data chapter in the Forcepoint Network Security Platform Product Guide. The behavior when remaining audit storage space starts to become low is as follows:

  • Log Server — When the remaining audit storage space drops below 300MB, an alert is sent to administrators. When less than 100MB of space remains, the Log Server stops accepting new audit messages from Security Engines. The administrator has to take action to remove old audit records.
  • Management Server — When less than 100MB of audit storage space remains, the Management Server prevents the administrator from making further changes. The administrator has to take action to remove old audit records.