Endpoint Protection Small Business Edition

 View Only
  • 1.  traffic folder SEPM

    Posted Nov 17, 2013 10:01 PM
      |   view attached
    good
     
    traffic folder currently located in the following path:
    \ Program Files \ Symantec \ Symantec Endpoint Protection Manager \ data \ inbox \ log \ traffic,
     
    its size is about 50 GB, in the Inner many files error, as shown in the attachment, I can indicate which files I can delete and if I should jenerar a support case for these files
     
    thanks 

    Attachment(s)

    docx
    log error.docx   71 KB 1 version


  • 2.  RE: traffic folder SEPM

    Posted Nov 17, 2013 10:04 PM

    Check mithun comments on this same issue releated thread

    https://www-secure.symantec.com/connect/forums/sep-121-space-issues



  • 3.  RE: traffic folder SEPM

    Posted Nov 17, 2013 10:06 PM

    What SEPM version are you on?

    1. Stop the SEPM service
    2. Remove .dat files in all folders
    3. Kill bcp.exe processes
    4. Open \Program files\Symantec\Symantec Endpoint Protection Manager\tomcat\etc\conf.properties in a text editor
    5. Add line "scm.log.batchmode=1" to stop bcp.exe from being used in future
    6. Start SEPM service.

     

    Checking the inbox logs on the management server

    http://www.symantec.com/docs/HOWTO55025

    About increasing the space by adjusting the amount of client log data

    http://www.symantec.com/docs/HOWTO55339



  • 4.  RE: traffic folder SEPM

    Posted Nov 20, 2013 06:47 AM

    The folder contains traffic log files send by SEP clients to SEPM for processing. Due to errors (may be several different causes - if you want to investigate that I would recommend opening case with Support), SEPM was not able to process these - in such case the legitimate files are being renamed to .err files.

    You can try to rename them back to original extension (quite tedious with high amount of files) or delete them and monitor if problem is reoccuring. Further check with database is recommended - commonly problems are on this side where SQL file tables have reached maximum allowe size or when the SQL native client or SEPM server is malfunctioning (reinstalling of this one can help as well).



  • 5.  RE: traffic folder SEPM

    Broadcom Employee
    Posted Nov 20, 2013 06:57 AM

    are there files with extension .err?



  • 6.  RE: traffic folder SEPM

    Trusted Advisor
    Posted Dec 02, 2013 08:46 AM

    Hello,

    Was there a migration which was done from SEP 11.x?

    You may edit the firewall policies to disable logging for any rules where this is no longer needed.

    Secondly,  In SEPM >> Admin >> Servers >> localhost >> Edit Database Properties >> Log Settings

    Change the 50,000 entries change that to 10,000 or 5000

    The traffic Logs would be set for 60 days change that to 10 days

    Then it should bring down the size.

    Hope that helps!!