Endpoint Protection

 View Only
  • 1.  Huge log files

    Posted Mar 07, 2012 04:01 PM

    I have a ton of log files in C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\apache\logs

    Most start with access-2011-***.log

    Can I delete these and do I need to turn down logging? I don't know why they are so big?

     

    SEPM 12.1 RU1



  • 2.  RE: Huge log files

    Posted Mar 07, 2012 05:28 PM

    You may want to remove debugging.. may that's what causing the issue.



  • 3.  RE: Huge log files

    Broadcom Employee
    Posted Mar 07, 2012 10:07 PM

    is the logging set to finest in conf.properties under the tomcat\etc\folder? if yes set it to fine



  • 4.  RE: Huge log files
    Best Answer

    Posted Mar 08, 2012 04:55 AM

    Hi Brian,

     

    The following article may help.  It exaplains how to enable Apache access loggign.... it sounds like that may be what is happening on that SEPM.  Just reverse the steps to disable it:

    Symantec Endpoint Protection Manager 12.1 Communication Troubleshooting
    Article: TECH160964   |  Created: 2011-05-26   |  Updated: 2011-12-06   | 
    Article URL http://www.symantec.com/docs/TECH160964

     

    Enabling and viewing the Access log to check whether the client connects to the management server

    You can view the Apache HTTP server Access log on the management server to check whether the client connects to the management server. If the client connects, the client's connection problem is probably not a network issue. Network issues include the firewall blocking access, or networks not connecting to each other. You must first enable the Apache HTTP server Access log before you can view the log.

    Note: Disable the log after you view it because the log uses unnecessary CPU resources and hard disk space.

    To enable the Apache HTTP server Access log:

    1.In a text editor, open the file
    C:\Program Files\Symantec\Symantec Endpoint Protection Manager\apache\conf\httpd.conf.

    2.In the httpd.conf file, remove the hash mark (#) from the following text string and then save the file:
    #CustomLog "logs/access.log" combined

    3.Using services.msc, restart the Symantec Endpoint Protection Manager Webserver service (Apache)
    Click "Yes" to also restart the SEPM service

    To view the Apache HTTP server Access log:

    1.On the management server, open
    C:\Program Files\Symantec\Symantec Endpoint Protection Manager\apache\access.log

    2.Look for a client computer's IP address or host name, which indicates that clients connect to the Apache HTTP server.

    3.Disable the Apache HTTP server Access log when done
     


     



  • 5.  RE: Huge log files

    Posted Mar 08, 2012 06:33 AM

    Apache Web Server Logs
    Article: TECH94290   |  Created: 2009-01-01   |  Updated: 2011-07-08   | 
    Article URL http://www.symantec.com/docs/TECH94290 
     



  • 6.  RE: Huge log files

    Posted Mar 08, 2012 08:18 AM

    By default Apache Server generates only Error logs and stored in C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\apache\logs

    If you have enabled access log or communication log and you have many clients then there is a possiblity that Logs folder is huge in size.

    Could you let us know what is the size of the Logs folder?



  • 7.  RE: Huge log files

    Posted Mar 08, 2012 08:32 AM

    It's set to fine



  • 8.  RE: Huge log files

    Posted Mar 08, 2012 08:33 AM

    I made this change in the httpd.conf because that was what was recommended for the GUP monitor to work.



  • 9.  RE: Huge log files

    Posted Mar 08, 2012 08:34 AM

    It is about 31.5GB