What it is ? Why is it needed? How critical is it?

Hello, I need your advice.

I don't know enough about such things, so please advise. I received a letter from ESM with a warning: EventArchive location /opt/arcsight/logger/data/archives/ has used 99% of the cap space. Please free up some cap by moving eventarchive directories to some other place.

Is this situation critical? Is there a solution without moving the catalogs with the archive?

Thanks in advance

Bohdan

Parents Reply
  • Verified Answer

    +1   in reply to 

    Yes, the event data would get archived on a daily basis from when you have setup archives.  It would be your choice if you decide you need this archived data or not.  If you never plan to go back that far and search the older archived events and if you don't need it for any compliance reasons, then you probably would not need it.  Again, that would be something for you to determine.  

Children
No Data