IBM QRadar

 View Only

 Need to automate clearing of exported logs from storage.

Richard Diring's profile image
Richard Diring posted Mon December 09, 2024 01:32 PM

Running on prem storage. Not looking to move to cloud storage, as not within budget.

Need to clear out the export queue after two days, but unable to find where such configuration can be made.

Submitted ticket to IBM, and was told would have to contact IBM Expert Labs. That led me to this forum link.

John Dawson's profile image
John Dawson

Hi Richard

The exports should be in a /store/exports folder

You may be able to use a standard linux command such as

find /store/exports/* -mtime +2 -exec rm {} \;To remove files older than 2 days.  You could then add a cron job so this would run nightly.

This however would need to be tested.

Thanks