ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.
Can anyone tell me where log files are generated and stored for Linux installations? We had an incident and I'm not sure if this was due to excessive logging or not. Xinetd was blocked by default policy which started Friday afternoon. Today when we came in one of the drives was full although not sure from what.
I used /opt directory for traps installer and there is now a directory in /opt named Traps with a bunch of folders. only 5GB in space total.
Any assistance would be much appreciated. Using 188.8.131.525 version for Linux installs.
Thank you thomaskoetsier. I guess my question was do logs from blocked traffic or activity get logged in log files directly on the server and if so how large does the repository for logs get or where is it? If it's only 5G then I don't think the logs were the culprit. I wasn't looking to check logs at all I was more curious how large this grows. No changes were made to any configuration of logs etc so whatever default values there are, that is what is set at the moment.
@efrancis Does this go the same for blocked processes? Xinetd being blocked, would that have generated a ton of logs that are sitting directly on the server? Also when you mention the quota for the folder that logs are stored in is audited hourly, does this mean there are logs on the server that do accumulate or do you mean they are purged to a point after reaching a max size of xGB?
Thank you for the replies!
First, I would recommend to reach out to Palo Alto Endpoint support. They are a great team of engineers that can help determine any issues you may be facing. The quota part is for all of the Traps agent folders, which contains the logs. Normally the quarantine folder would the culprit of space being taken up. Again, the support team can help answer these questions, and are available for a remote session, if you think that will resolve the issue faster.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!