Windows 'sisipsservice' log is not being removed
search cancel

Windows 'sisipsservice' log is not being removed

book

Article ID: 372428

calendar_today

Updated On:

Products

Data Center Security Server Advanced

Issue/Introduction

If you have bulklogging rotation enabled in your Data Center Security Common Parameters Configuration file with and IDS policy, you may notice that the 'sisipsservice' log is not being removed and causing space consumption on the server. 

Cause

If the same file is monitored as a normal file, IDS will not monitor it as a log file. This is by design. the customer can modify his IDS policy to not monitor the "agentlog" and "sdcsslog" folder as a workaround.

Resolution

Remove the following values from file monitoring in the IDS policy.

%%HKEY_LOCAL_MACHINE\Software\symantec\intrusion security\Agent\InstallRoot%%\*
%%HKEY_LOCAL_MACHINE\Software\symantec\intrusion security\Agent\LogInstallRoot%%\*

-Windows Baseline Detection Policy
-'System Symantec Software Monitoring' section
-'Monitor DCS Files' section
-Remove the values above and reapply the policy.