Troubleshooting: What Logs/Files Can Be Cleaned From a SecureAuth IdP Server?

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Logging on a SecureAuth Identity Provider (IdP) server can use a large amount of disk space over time. This article lists where SecureAuth IdP logging is stored on an on-premises appliance, and gives guidance on managing that log growth.
     
     

    Cause

    The SecureAuth IdP is a security appliance, so it keeps standard logging in place by default so administrators can investigate issues if they arise. Additional logging may also be turned on for a debug session. Over time, both standard and debug logs accumulate and consume disk space, so it helps to know what exists and where.
     
     

    Resolution

    The following locations are where logging occurs on a SecureAuth IdP deployment. Not every path listed will exist on every server — it depends on which components are installed and which version is running.

    SecureAuth IdP Server (per realm):

    • D:\SecureAuth\<REALM_#>\AuditLogs\
    • D:\SecureAuth\<REALM_#>\DebugLogs\
    • D:\SecureAuth\<REALM_#>\ErrorLogs\

    Internet Information Services (IIS), the web server hosting the IdP:

    • D:\inetpub\logs\logfiles\W3SVC1\

    SecureAuth RADIUS Server, if installed:

    • <INSTALL_DIRECTORY>\bin\logs\

    SecureAuth Updater, on versions where it is used:

    • D:\MFCApp_Bin\SecureAuth_Update

    SecureAuth archive and backup files:

    • D:\MFCApp_Bin\SecureAuth_Archive


     

    Special Considerations

    Rather than deleting logs outright, it is good practice to retain them for some period of time. A common approach is to script a weekly or monthly job that compresses the logs and ships the package to a network share or file server, in case they are needed for review later.
     

    The SecureAuth IdP can also log to a SQL Server database, which a database administrator can maintain using regular SQL Server maintenance instead of manual file cleanup — see Logging Database Configuration. IIS logging can similarly be redirected to a SQL Server database; see Microsoft's How To Configure ODBC Logging in IIS article. A SecureAuth IdP server does not have IIS Open Database Connectivity (ODBC) logging enabled by default — ODBC logging support must be installed first, which is also where that Microsoft article's logtemp.sql script comes from.
     

    For related step-by-step procedures, see How To: Configure Local Text Logging Timestamp, Rollover, and Retention and How To: Bulk-Delete Old SecureAuth Log Files.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.