简介
本文档介绍如何在思科邮件安全设备(ESA)上提高报告和跟踪数据保留率以允许数据重叠。
先决条件
Cisco 建议您了解以下主题:
报告数据
当SMA离线或不可达时,ESA开始将报告数据排入队列。默认情况下,ESA保留100个文件,每个文件有15分钟的持续时间。基本上,ESA保留当前1,500分钟(15 x 100)的数据,相当于25小时。如果SMA关闭30小时,则会丢失前5小时(30小时- 25小时)的报告数据。
使用此示例中的信息可增加ESA上保留的文件数:
example.com> reportingconfig
Choose the operation you want to perform:
- MAILSETUP - Configure reporting for the ESA.
- MODE - Enable centralized or local reporting for the ESA.
[]> mailsetup
SenderBase timeout used by the web interface: 2 seconds
Sender Reputation Multiplier: 3
The current level of reporting data recording is: unlimited
No custom second level domains are defined.
Legacy mailflow report: Disabled
Choose the operation you want to perform:
- SENDERBASE - Configure SenderBase timeout for the web interface.
- MULTIPLIER - Configure Sender Reputation Multiplier.
- COUNTERS - Limit counters recorded by the reporting system.
- THROTTLING - Limit unique hosts tracked for rejected connection reporting.
- TLD - Add customer specific domains for reporting rollup.
- STORAGE - How long centralized reporting data will be stored on the C-series
before being overwritten.
- LEGACY - Configure legacy mailflow report.
[]> storage
While in centralized mode the C-series will store reporting data for the
M-series to collect. If the M-series does not collect that data then
eventually the C-series will begin to overwrite the oldest data with
new data.
A maximum of 24 hours of reporting data will be stored.
How many hours of reporting data should be stored before data loss?
[24]> 30
跟踪数据
同样,当SMA脱机或不可达时,ESA会开始将跟踪数据排入队列。ESA保留60个文件,每个文件有3分钟的持续时间。因此,ESA保留过去180分钟(60 x 3)的数据。未从ESA检索且超过三个小时的所有跟踪数据都将丢失。
使用此示例中的信息可增加跟踪文件的最大数量:
example.com> trackingconfig
Choose the operation you want to perform:
- MODE - Set whether tracking is run on box or centralized.
[]> storage
While in centralized mode the C-series will store tracking data for the
M-series to collect. If the M-series does not collect that data then
eventually the C-series will begin to overwrite the oldest data with new
data.
A maximum of 60 files are presently stored. This means a maximum of 3 hours
will be stored, though depending on load that time may be smaller.
How many files should be stored before data loss?
[60]> 500
相关信息