Logs getting deleted after 7 days #12417
Replies: 3 comments 7 replies
-
Depending on the size of the disk, you might be running into size-based deletion - https://docs.securityonion.net/en/2.4/elasticsearch.html#size-based-index-deletion |
Beta Was this translation helpful? Give feedback.
4 replies
-
That could definitely be it! How would I go about changing it? |
Beta Was this translation helpful? Give feedback.
3 replies
-
Check your default retention value in Elasticsearch it is probably set to like 50% not sure wy the default is so low |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Any idea why my logs are getting deleted after around 7 days? I thought that I had the deleted logs set to 120 days?
Let me know if there is a different area that could be doing this and not just under ElasticSearch. Thanks ahead of time for the help!
Beta Was this translation helpful? Give feedback.
All reactions