CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-10
khunkao khunkao is offline
Junior Member
 
Join Date: 2006-09-19
Posts: 6
Rep Power: 0
khunkao has an average reputation (10+)
Default getting rid of old logs

I have Checkpoint NG FW1 running in Windows 2000. Unfortunately the partition it has been sitting on is just small and I am now finding log files that date back 5 years ago! I need to delete these logs, their associated ptr and audit files. Do I simply run cpstop, delete them and then cpstart?
Reply With Quote
  #2 (permalink)  
Old 2006-11-10
Joncon Joncon is offline
Senior Member
 
Join Date: 2006-06-08
Location: UK
Posts: 149
Rep Power: 3
Joncon has an average reputation (10+)
Default Re: getting rid of old logs

Before deleting them make sure there are no regulatory obligations on your organisation regarding the retention of logs. I'm thinking SoX, BAsel, FSA etc. If in doubt speak to your compliance department.
Reply With Quote
  #3 (permalink)  
Old 2006-11-10
khunkao khunkao is offline
Junior Member
 
Join Date: 2006-09-19
Posts: 6
Rep Power: 0
khunkao has an average reputation (10+)
Default Re: getting rid of old logs

nope there are no regulations. So should I just cpstop, delete the files or at least move them off the directory, then cpstart?
Reply With Quote
  #4 (permalink)  
Old 2006-11-10
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: getting rid of old logs

If the logs have been rotated regularly - i.e. we're not talking about deleting fw.log - then you can just delete them. No need to do a cpstop.

Do yourself a favour and script this.

If you do need to keep them longer, one tip is to gzip them - they go down to around 10% of their size.

Do yourself another favour and get that box upgraded too...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0