By default, Firewall Insights stores log data from connected devices in compressed form (approx. 1/10 of the original size) in the server database for 6 months, according to the default log retention period. Data older than 6 months are automatically deleted. The Kafka log retention period relates to how long uncompressed data from devices should be stored on the Firewall Insights server. Logs stored on the server can be recovered for informational purposes if necessary. You can re-import the data for the configured time frame. Uncompressed files are approximately a factor of 10 larger than compressed files and are not used for graphs or reports.
Configure the Retention Policy
- Navigate to BASIC > Administration.
- Scroll down to the Connected Devices section.
- For all devices, select the Log Retention Period. The default value is 6 months (recommended). You can expand the log retention period up to 12 months but consider that longer log retention requires more resources.
- If required, set the Kafka Log Retention Period in hours. The default value is 30 days (720 hours) for Firewall Insights version 1.2.0 and earlier, and 7 days (168 hours, recommended) for version 1.2.1 and higher. To save disk space, use a low value for this setting.
- Click Save Changes.
Reducing the log retention period deletes all logs older than the new retention period specified (e.g., changing from 6 months to 1 month deletes all logs older than 1 month). Consider backing up logs before reducing the retention period. Increasing the log retention period adds new logs to the collection, up to the period specified. Your data will be preserved as much as possible, but some data will be lost. When storage capacity is reached, the oldest logs are deleted first.
Check the Storage Capacity
To view storage used for the logs from each connected Barracuda device:
- Navigate to BASIC > General.
- Locate the Connected Devices area.
- For each connected device, you will see the storage space used for its stored logs on the dashboard.