簡介
本文檔介紹如何在思科郵件安全裝置(ESA)上提高報告和跟蹤資料保留率,以允許資料重疊。
必要條件
思科建議您瞭解以下主題:
- Cisco ESA
- 思科內容安全管理裝置(SMA)
報告資料
當SMA離線或不可達時,ESA開始將報告資料排入隊列。ESA預設保留100個檔案,每個檔案有15分鐘的持續時間。基本上,ESA保留當前1,500分鐘(15 x 100)的資料,相當於25小時。如果SMA中斷30小時,則前5小時(30小時- 25小時)將丟失報告資料。
使用本示例中的資訊以增加ESA上保留的檔案數:
example.com> reportingconfig
Choose the operation you want to perform:
- MAILSETUP - Configure reporting for the ESA.
- MODE - Enable centralized or local reporting for the ESA.
[]> mailsetup
SenderBase timeout used by the web interface: 2 seconds
Sender Reputation Multiplier: 3
The current level of reporting data recording is: unlimited
No custom second level domains are defined.
Legacy mailflow report: Disabled
Choose the operation you want to perform:
- SENDERBASE - Configure SenderBase timeout for the web interface.
- MULTIPLIER - Configure Sender Reputation Multiplier.
- COUNTERS - Limit counters recorded by the reporting system.
- THROTTLING - Limit unique hosts tracked for rejected connection reporting.
- TLD - Add customer specific domains for reporting rollup.
- STORAGE - How long centralized reporting data will be stored on the C-series
before being overwritten.
- LEGACY - Configure legacy mailflow report.
[]> storage
While in centralized mode the C-series will store reporting data for the
M-series to collect. If the M-series does not collect that data then
eventually the C-series will begin to overwrite the oldest data with
new data.
A maximum of 24 hours of reporting data will be stored.
How many hours of reporting data should be stored before data loss?
[24]> 30
追蹤資料
同樣,當SMA離線或不可達時,ESA開始將跟蹤資料排入隊列。ESA保留60個檔案,每個檔案有3分鐘的持續時間。因此,ESA保留過去180分鐘(60 x 3)的資料。任何未從ESA檢索且超過三個小時的跟蹤資料都將丟失。
使用以下示例中的資訊以增加跟蹤檔案的最大數量:
example.com> trackingconfig
Choose the operation you want to perform:
- MODE - Set whether tracking is run on box or centralized.
[]> storage
While in centralized mode the C-series will store tracking data for the
M-series to collect. If the M-series does not collect that data then
eventually the C-series will begin to overwrite the oldest data with new
data.
A maximum of 60 files are presently stored. This means a maximum of 3 hours
will be stored, though depending on load that time may be smaller.
How many files should be stored before data loss?
[60]> 500
相關資訊