Symantec Privileged Access Management

 View Only
  • 1.  PAM Database Size Correlation to Clustering

    Posted Oct 17, 2022 02:43 AM
    I have PAM v4.1 clustering between 2 sites and have database dump around 2.6GB. Is that considered big or normal? I'm curious since mine have a very unstable cluster, with 50/50 chance of replication success.


  • 2.  RE: PAM Database Size Correlation to Clustering

    Broadcom Employee
    Posted Oct 17, 2022 05:19 AM

    Hello Jorghy,

    The DB size is not abnormal.
    Do you see any problems with your cluster setup? It's recommended to have an odd number of hosts per site to avoid any problems related to split brain.

    Thanks,
    Reatesh.




  • 3.  RE: PAM Database Size Correlation to Clustering

    Posted Oct 17, 2022 06:32 AM
    I have two sites with 3 nodes each.


  • 4.  RE: PAM Database Size Correlation to Clustering

    Broadcom Employee
    Posted Oct 17, 2022 01:54 PM
    Hi Jorghy, A large database can be problematic, if there is a poor network connection between PAM cluster nodes, typically between sites. With good connectivity a 2.6 GB backup file should not be a problem. A database of this size must be dominated by dynamic data rather than configuration items like devices, accounts and policies. Often the metric and auditlog data dominate the DB size, and their size in turn is controlled by the auto-archive settings on the Settings > Credential Manager > Auto-Archive page. First of all make sure your auto-archive share is defined (PAM is using the session recording share), and auto-archiving works. If this is true, see whether you can reduce the age setting. There also is a Password View Request Delete Interval Days setting under General Settings that you may be able to reduce. These settings will impact what data you can retrieve using Credential Manager reports (Credentials > Reports). It is possible that you have other large dynamic data tables that are not affected by purge policies. Open a case with PAM Support if needed, to get more insight into what exactly causes your DB to have this relatively large size.


  • 5.  RE: PAM Database Size Correlation to Clustering

    Posted Oct 17, 2022 10:39 PM
    There shouldn't be any issue regarding network connection since it's belong to telco company. I also leave the default value for "Password View Request Delete Interval Days = 30" and "Auto-archive = 7 days".