<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Storage is full from a Cyvera Log file with 706.1GB size in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storage-is-full-from-a-cyvera-log-file-with-706-1gb-size/m-p/1254022#M9336</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150582845"&gt;@D.Patel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="qMYqUG_convSearchResultHighlightRoot"&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0"&gt;
&lt;DIV class="relative w-full overflow-visible"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-scroll-anchor="false" data-testid="conversation-turn-2" data-turn-id-container="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0" data-turn-id="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-5" data-message-id="92bee8dd-41af-4ec9-9205-b5ef8f2d95c1" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling"&gt;
&lt;P data-end="353" data-start="0"&gt;While a 706GB log file is unusually large, excessive disk space consumption within the Cyvera (Cortex XDR Agent) data directory is a known issue documented across several support cases and internal reports.&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;The recurrence every Monday strongly suggests a correlation with a &lt;STRONG&gt;scheduled full scan or a periodic maintenance task&lt;/STRONG&gt; that triggers high activity.&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="379" data-start="355" data-section-id="192xsx"&gt;Potential Root Causes:&lt;/H4&gt;
&lt;P data-end="514" data-start="381"&gt;Based on internal resources, the following scenarios often lead to massive storage consumption in the &lt;CODE data-end="506" data-start="483"&gt;C:\ProgramData\Cyvera&lt;/CODE&gt; folder:&lt;/P&gt;
&lt;UL data-end="1675" data-start="516"&gt;
&lt;LI data-end="765" data-start="516" data-section-id="2pxf4p"&gt;&lt;STRONG data-end="538" data-start="518"&gt;Scheduled Scans:&lt;/STRONG&gt; A known issue exists where Cortex XDR agent scheduled scans cause the Cyvera folder to grow excessively (over 40GB in documented cases), often due to the agent's data purging mechanism failing to keep up with event generation.&lt;/LI&gt;
&lt;LI data-end="992" data-start="767" data-section-id="1yfo1ze"&gt;&lt;STRONG data-end="798" data-start="769"&gt;Database Pruning Failure:&lt;/STRONG&gt; Known bugs (such as CPATR-25516 and CPATR-27826) can cause internal databases in the Persistence folder to grow exponentially. Common offenders include &lt;CODE data-end="971" data-start="951"&gt;wf_verdicts.db.lru&lt;/CODE&gt; and &lt;CODE data-end="991" data-start="976"&gt;edr_fileid.db&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI data-end="1398" data-start="994" data-section-id="1qyi0on"&gt;&lt;STRONG data-end="1036" data-start="996"&gt;Alert Artifacts (Prevention Folder):&lt;/STRONG&gt; If an endpoint experiences a burst of alerts (for example during Windows updates or specific software activity), the agent may buffer a massive amount of forensic data and memory dumps in the Prevention folder. If connectivity to the management console is intermittent, these files bypass the standard disk quota and accumulate until the connection is restored.&lt;/LI&gt;
&lt;LI data-end="1675" data-start="1400" data-section-id="j106h2"&gt;&lt;STRONG data-end="1427" data-start="1402"&gt;Temporary File Leaks:&lt;/STRONG&gt; Files related to SandboxService (such as &lt;CODE data-end="1484" data-start="1469"&gt;tlaplugin.dll&lt;/CODE&gt;, &lt;CODE data-end="1509" data-start="1486"&gt;recognizer_plugin.dll&lt;/CODE&gt;) or "In-Flight" logs from failed Technical Support File (TSF) collections can fail to clean up, leading to multi-gigabyte growth in the &lt;CODE data-end="1664" data-start="1646"&gt;LocalSystem\Temp&lt;/CODE&gt; directory.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1719" data-start="1677" data-section-id="978dwj"&gt;Recommended Troubleshooting and Cleanup&lt;/H4&gt;
&lt;P data-end="1831" data-start="1721"&gt;To safely reclaim space, you typically must disable the agent's self-protection to release locks on the files.&lt;/P&gt;
&lt;H4 data-end="1860" data-start="1833" data-section-id="p6zcrl"&gt;1. Identify the Culprit:&lt;/H4&gt;
&lt;P data-end="1950" data-start="1862"&gt;Navigate to the following directory to determine which subfolder is consuming the space:&amp;nbsp;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;C:\ProgramData\Cyvera\&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1994" data-start="1988"&gt;Check:&lt;/P&gt;
&lt;UL data-end="2145" data-start="1996"&gt;
&lt;LI data-end="2052" data-start="1996" data-section-id="1d1yxia"&gt;&lt;CODE data-end="2023" data-start="1998"&gt;LocalSystem\Persistence&lt;/CODE&gt; (for &lt;CODE data-end="2034" data-start="2029"&gt;.db&lt;/CODE&gt; and &lt;CODE data-end="2045" data-start="2039"&gt;.lru&lt;/CODE&gt; files)&lt;/LI&gt;
&lt;LI data-end="2092" data-start="2053" data-section-id="k4mxxs"&gt;&lt;CODE data-end="2067" data-start="2055"&gt;Prevention&lt;/CODE&gt; (for forensic artifacts)&lt;/LI&gt;
&lt;LI data-end="2145" data-start="2093" data-section-id="1vw97ee"&gt;&lt;CODE data-end="2113" data-start="2095"&gt;LocalSystem\Temp&lt;/CODE&gt; (for temporary or Sandbox logs)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2178" data-start="2147" data-section-id="kvpdd9"&gt;2. Manual Cleanup Procedure:&lt;/H4&gt;
&lt;P data-end="2310" data-start="2180"&gt;If the "Clear Agent Database" action from the console is ineffective, perform the following steps locally on the affected machine:&lt;/P&gt;
&lt;OL data-end="2399" data-start="2312"&gt;
&lt;LI data-end="2352" data-start="2312" data-section-id="16hmlm2"&gt;Open Command Prompt as Administrator.&lt;/LI&gt;
&lt;LI data-end="2399" data-start="2354" data-section-id="ids7ig"&gt;Navigate to the Traps installation folder:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cd "C:\Program Files\Palo Alto Networks\Traps"&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="3" data-end="2533" data-start="2460"&gt;
&lt;LI data-end="2533" data-start="2460" data-section-id="1d0mao"&gt;Disable tamper protection (requires the endpoint supervisor password):&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool protect disable&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="4" data-end="2597" data-start="2570"&gt;
&lt;LI data-end="2597" data-start="2570" data-section-id="u5mzar"&gt;Stop the agent services:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool runtime stop&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="5" data-end="2801" data-start="2631"&gt;
&lt;LI data-end="2801" data-start="2631" data-section-id="3ha1ix"&gt;Delete the contents of the identified problematic folder (for example &lt;CODE data-end="2753" data-start="2704"&gt;C:\ProgramData\Cyvera\LocalSystem\Persistence\*&lt;/CODE&gt; or &lt;CODE data-end="2799" data-start="2757"&gt;C:\ProgramData\Cyvera\LocalSystem\Temp\*&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2845" data-start="2803"&gt;&lt;STRONG&gt;Note :&lt;/STRONG&gt; (Do not delete the root folders themselves).&lt;/P&gt;
&lt;P data-end="2845" data-start="2803"&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="6" data-end="2877" data-start="2847"&gt;
&lt;LI data-end="2877" data-start="2847" data-section-id="4ut0ke"&gt;Restart the agent services:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool runtime start&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="7" data-end="2943" data-start="2912"&gt;
&lt;LI data-end="2943" data-start="2912" data-section-id="1sfzftt"&gt;Re-enable tamper protection: &lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool protect enable&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4 data-end="3001" data-start="2979" data-section-id="1pij0ai"&gt;Preventive Measures:&lt;/H4&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="3563" data-start="3003"&gt;
&lt;LI data-end="3195" data-start="3003" data-section-id="1kafogo"&gt;&lt;STRONG data-end="3027" data-start="3005"&gt;Check Disk Quotas:&lt;/STRONG&gt; Ensure the "Agent Disk Quota" in the Agent Settings profile is set to at least 5000 MB. While some artifacts bypass this limit, it still governs standard log rotation.&lt;/LI&gt;
&lt;LI data-end="3344" data-start="3197" data-section-id="alet73"&gt;&lt;STRONG data-end="3221" data-start="3199"&gt;Upgrade the Agent:&lt;/STRONG&gt; Many database growth and cleanup bugs (including CPATR-27578 and CPATR-25516) are fixed in version 8.7 or 9.0.0 and later.&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="3563" data-start="3346" data-section-id="iyncve"&gt;&lt;STRONG data-end="3376" data-start="3348"&gt;Analyze Scheduled Scans:&lt;/STRONG&gt; Since the issue recurs every Monday, review the scan configuration in the Malware profile and inspect &lt;CODE data-end="3491" data-start="3479"&gt;trapsd.log&lt;/CODE&gt; for errors indicating the purging mechanism is failing during the scan.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;like&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2026 12:37:05 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-05-14T12:37:05Z</dc:date>
    <item>
      <title>Storage is full from a Cyvera Log file with 706.1GB size</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storage-is-full-from-a-cyvera-log-file-with-706-1gb-size/m-p/1253929#M9334</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Storage is full from a Cyvera Log file with 706.1GB size this seems to happen every Monday, very odd. We've been wiping it manually for the person to continue working. &lt;BR /&gt;&lt;BR /&gt;Anyone encounter this issue before?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DPatel_0-1778688501900.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71411iBDD90A71110BF5AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DPatel_0-1778688501900.png" alt="DPatel_0-1778688501900.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2026 16:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storage-is-full-from-a-cyvera-log-file-with-706-1gb-size/m-p/1253929#M9334</guid>
      <dc:creator>D.Patel</dc:creator>
      <dc:date>2026-05-13T16:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Storage is full from a Cyvera Log file with 706.1GB size</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storage-is-full-from-a-cyvera-log-file-with-706-1gb-size/m-p/1254022#M9336</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150582845"&gt;@D.Patel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="qMYqUG_convSearchResultHighlightRoot"&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0"&gt;
&lt;DIV class="relative w-full overflow-visible"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-scroll-anchor="false" data-testid="conversation-turn-2" data-turn-id-container="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0" data-turn-id="request-WEB:01e36bf1-8757-4f8e-8098-730684032c04-0"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-5" data-message-id="92bee8dd-41af-4ec9-9205-b5ef8f2d95c1" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling"&gt;
&lt;P data-end="353" data-start="0"&gt;While a 706GB log file is unusually large, excessive disk space consumption within the Cyvera (Cortex XDR Agent) data directory is a known issue documented across several support cases and internal reports.&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;The recurrence every Monday strongly suggests a correlation with a &lt;STRONG&gt;scheduled full scan or a periodic maintenance task&lt;/STRONG&gt; that triggers high activity.&lt;/P&gt;
&lt;P data-end="353" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="379" data-start="355" data-section-id="192xsx"&gt;Potential Root Causes:&lt;/H4&gt;
&lt;P data-end="514" data-start="381"&gt;Based on internal resources, the following scenarios often lead to massive storage consumption in the &lt;CODE data-end="506" data-start="483"&gt;C:\ProgramData\Cyvera&lt;/CODE&gt; folder:&lt;/P&gt;
&lt;UL data-end="1675" data-start="516"&gt;
&lt;LI data-end="765" data-start="516" data-section-id="2pxf4p"&gt;&lt;STRONG data-end="538" data-start="518"&gt;Scheduled Scans:&lt;/STRONG&gt; A known issue exists where Cortex XDR agent scheduled scans cause the Cyvera folder to grow excessively (over 40GB in documented cases), often due to the agent's data purging mechanism failing to keep up with event generation.&lt;/LI&gt;
&lt;LI data-end="992" data-start="767" data-section-id="1yfo1ze"&gt;&lt;STRONG data-end="798" data-start="769"&gt;Database Pruning Failure:&lt;/STRONG&gt; Known bugs (such as CPATR-25516 and CPATR-27826) can cause internal databases in the Persistence folder to grow exponentially. Common offenders include &lt;CODE data-end="971" data-start="951"&gt;wf_verdicts.db.lru&lt;/CODE&gt; and &lt;CODE data-end="991" data-start="976"&gt;edr_fileid.db&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI data-end="1398" data-start="994" data-section-id="1qyi0on"&gt;&lt;STRONG data-end="1036" data-start="996"&gt;Alert Artifacts (Prevention Folder):&lt;/STRONG&gt; If an endpoint experiences a burst of alerts (for example during Windows updates or specific software activity), the agent may buffer a massive amount of forensic data and memory dumps in the Prevention folder. If connectivity to the management console is intermittent, these files bypass the standard disk quota and accumulate until the connection is restored.&lt;/LI&gt;
&lt;LI data-end="1675" data-start="1400" data-section-id="j106h2"&gt;&lt;STRONG data-end="1427" data-start="1402"&gt;Temporary File Leaks:&lt;/STRONG&gt; Files related to SandboxService (such as &lt;CODE data-end="1484" data-start="1469"&gt;tlaplugin.dll&lt;/CODE&gt;, &lt;CODE data-end="1509" data-start="1486"&gt;recognizer_plugin.dll&lt;/CODE&gt;) or "In-Flight" logs from failed Technical Support File (TSF) collections can fail to clean up, leading to multi-gigabyte growth in the &lt;CODE data-end="1664" data-start="1646"&gt;LocalSystem\Temp&lt;/CODE&gt; directory.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1719" data-start="1677" data-section-id="978dwj"&gt;Recommended Troubleshooting and Cleanup&lt;/H4&gt;
&lt;P data-end="1831" data-start="1721"&gt;To safely reclaim space, you typically must disable the agent's self-protection to release locks on the files.&lt;/P&gt;
&lt;H4 data-end="1860" data-start="1833" data-section-id="p6zcrl"&gt;1. Identify the Culprit:&lt;/H4&gt;
&lt;P data-end="1950" data-start="1862"&gt;Navigate to the following directory to determine which subfolder is consuming the space:&amp;nbsp;&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;C:\ProgramData\Cyvera\&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1994" data-start="1988"&gt;Check:&lt;/P&gt;
&lt;UL data-end="2145" data-start="1996"&gt;
&lt;LI data-end="2052" data-start="1996" data-section-id="1d1yxia"&gt;&lt;CODE data-end="2023" data-start="1998"&gt;LocalSystem\Persistence&lt;/CODE&gt; (for &lt;CODE data-end="2034" data-start="2029"&gt;.db&lt;/CODE&gt; and &lt;CODE data-end="2045" data-start="2039"&gt;.lru&lt;/CODE&gt; files)&lt;/LI&gt;
&lt;LI data-end="2092" data-start="2053" data-section-id="k4mxxs"&gt;&lt;CODE data-end="2067" data-start="2055"&gt;Prevention&lt;/CODE&gt; (for forensic artifacts)&lt;/LI&gt;
&lt;LI data-end="2145" data-start="2093" data-section-id="1vw97ee"&gt;&lt;CODE data-end="2113" data-start="2095"&gt;LocalSystem\Temp&lt;/CODE&gt; (for temporary or Sandbox logs)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2178" data-start="2147" data-section-id="kvpdd9"&gt;2. Manual Cleanup Procedure:&lt;/H4&gt;
&lt;P data-end="2310" data-start="2180"&gt;If the "Clear Agent Database" action from the console is ineffective, perform the following steps locally on the affected machine:&lt;/P&gt;
&lt;OL data-end="2399" data-start="2312"&gt;
&lt;LI data-end="2352" data-start="2312" data-section-id="16hmlm2"&gt;Open Command Prompt as Administrator.&lt;/LI&gt;
&lt;LI data-end="2399" data-start="2354" data-section-id="ids7ig"&gt;Navigate to the Traps installation folder:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cd "C:\Program Files\Palo Alto Networks\Traps"&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="3" data-end="2533" data-start="2460"&gt;
&lt;LI data-end="2533" data-start="2460" data-section-id="1d0mao"&gt;Disable tamper protection (requires the endpoint supervisor password):&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool protect disable&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="4" data-end="2597" data-start="2570"&gt;
&lt;LI data-end="2597" data-start="2570" data-section-id="u5mzar"&gt;Stop the agent services:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool runtime stop&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="5" data-end="2801" data-start="2631"&gt;
&lt;LI data-end="2801" data-start="2631" data-section-id="3ha1ix"&gt;Delete the contents of the identified problematic folder (for example &lt;CODE data-end="2753" data-start="2704"&gt;C:\ProgramData\Cyvera\LocalSystem\Persistence\*&lt;/CODE&gt; or &lt;CODE data-end="2799" data-start="2757"&gt;C:\ProgramData\Cyvera\LocalSystem\Temp\*&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2845" data-start="2803"&gt;&lt;STRONG&gt;Note :&lt;/STRONG&gt; (Do not delete the root folders themselves).&lt;/P&gt;
&lt;P data-end="2845" data-start="2803"&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="6" data-end="2877" data-start="2847"&gt;
&lt;LI data-end="2877" data-start="2847" data-section-id="4ut0ke"&gt;Restart the agent services:&lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool runtime start&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="7" data-end="2943" data-start="2912"&gt;
&lt;LI data-end="2943" data-start="2912" data-section-id="1sfzftt"&gt;Re-enable tamper protection: &lt;CODE style="color: #3e3e3e; font-size: 13px;"&gt;cytool protect enable&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4 data-end="3001" data-start="2979" data-section-id="1pij0ai"&gt;Preventive Measures:&lt;/H4&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="3563" data-start="3003"&gt;
&lt;LI data-end="3195" data-start="3003" data-section-id="1kafogo"&gt;&lt;STRONG data-end="3027" data-start="3005"&gt;Check Disk Quotas:&lt;/STRONG&gt; Ensure the "Agent Disk Quota" in the Agent Settings profile is set to at least 5000 MB. While some artifacts bypass this limit, it still governs standard log rotation.&lt;/LI&gt;
&lt;LI data-end="3344" data-start="3197" data-section-id="alet73"&gt;&lt;STRONG data-end="3221" data-start="3199"&gt;Upgrade the Agent:&lt;/STRONG&gt; Many database growth and cleanup bugs (including CPATR-27578 and CPATR-25516) are fixed in version 8.7 or 9.0.0 and later.&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="3563" data-start="3346" data-section-id="iyncve"&gt;&lt;STRONG data-end="3376" data-start="3348"&gt;Analyze Scheduled Scans:&lt;/STRONG&gt; Since the issue recurs every Monday, review the scan configuration in the Malware profile and inspect &lt;CODE data-end="3491" data-start="3479"&gt;trapsd.log&lt;/CODE&gt; for errors indicating the purging mechanism is failing during the scan.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;like&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 12:37:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storage-is-full-from-a-cyvera-log-file-with-706-1gb-size/m-p/1254022#M9336</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-05-14T12:37:05Z</dc:date>
    </item>
  </channel>
</rss>

