IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Guardium Database Internal

    Posted Wed April 12, 2023 11:35 PM
    Hello to all
     
    I have the following questions.
     
    What is the maximum size of the Gaurdium internal database?
     
    What is the maximum size for a table in the Guardium Turbine database? 
     
    In order to answer these questions, the Guardium user/client requires to store at least one year of logs, currently the daily average generated is 80GB of logs due to business/legal requirements.


    ------------------------------
    Daniel Chinas Vega
    ------------------------------


  • 2.  RE: Guardium Database Internal

    Posted Thu April 13, 2023 05:34 AM

    Hi Daniel,

    You can check db utilization to see the total available storage for Guardium internal MySQL database in Manage-->System Monitor.

    Also you can have an df-h output if you collect system level must gather logs to see all the file system.

    For a table there is no max size until there is space in db. This is my understanding from MySQL perspective.

    Guardium will start sending health self monitoring alerts to Administrator with an expected internal database being full date e.g. You tables utilization is this much mb last 24 hours and expected that your database will be full in next 10 days.

    Hope this helps.

    Regards,
    Rizwan



    ------------------------------
    Rizwan Joo
    ------------------------------



  • 3.  RE: Guardium Database Internal

    Posted Thu April 13, 2023 12:14 PM

    Hello Daniel:
    That's depend on the size of space of collector, you can size the machine with 2TB of HD in a Virtual Machine. As my experience, I make the collectors with 1TB all time. But the size of DB is direct on size of information that you collect. In the policies you must discriminate the relevant information that you  monitor. 
    I have a 2 months of retention data in the collector, and daily I archive the data to an SFTP server. If an auditor request information about old data, I download from SFTP to an special collector where I made the reports that the auditor needs.
    Based on this, I think that the one year of retention isn't possible.

    Regards,




    ------------------------------
    Carlos Espinoza Chandia
    ------------------------------