My On Prem SEPM database log retention settings set for Audit Log Limit aren't being honored, and a manual way to clean up the AUDIT_LOG is needed.
search cancel

My On Prem SEPM database log retention settings set for Audit Log Limit aren't being honored, and a manual way to clean up the AUDIT_LOG is needed.

book

Article ID: 423608

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

My On Prem SEPM database log retention settings set for Audit Log aren't being honored, and a manual way to clean up the AUDIT_LOG is needed.

Environment

On Prem SEPM 14.3 and later

Cause

The text "Audit Log Limit" listed in the On Prem SEPM Database Properties section actually correlates to the "Policy Log Limit" in error. This typo is being addressed in a future release of the product for consistency. 

Resolution

The Audit Log Limit isn't set from within the SEPM console, instead it is controlled by the SEPM configuration file (conf.properties).

To manually purge the logs from AUDIT_LOG you'll need to do the following: 

1. Open Notepad as Administrator
2. Navigate to C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\tomcat\etc\
3. Open conf.properties (SEPM config file) 
4. Next, edit the parameter called: "scm.audit.log.retention.in.days" and change the value "from" 365 days (default) "to" x (the total number of days you want these logs retained)
5. Once done, then restart the On Prem SEPM services. (In cases where one or more SEPMs exist in the site, you'll need to repeat steps 1-5 on "each" one for the changes to take effect)
6. After one day, the On Prem SEPM sweeping task should purge all the logs from the SEPM DB table AUDIT_LOG that are older than the number of days you specified in Step 4. 
7. If the issue persists then Contact Support