Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Endpoint Cleanup

This thread has been viewed 3 times
  • 1.  CPPM Endpoint Cleanup

    Posted Feb 26, 2018 11:42 AM

    Is there a report than can be ran to determine what endpoints are being cleaned up from the database durring the cleanup cycle?

     

    Thanks,

    Chris



  • 2.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 26, 2018 01:09 PM

    @ccalhounwrote:

    Is there a report than can be ran to determine what endpoints are being cleaned up from the database durring the cleanup cycle?

     

    Thanks,

    Chris


    I believe they would appear in the Audit Viewer.

    Monitoring -> Audit Viewer



  • 3.  RE: CPPM Endpoint Cleanup

    Posted Feb 26, 2018 02:14 PM

    Ok I have been watching that and also created a configuration change report. I changed the endpoint cleanup policy but am not seeing any changes on old stale endpoints. 

     

     



  • 4.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 26, 2018 02:20 PM

    Are these Known or Unknown endpoints?

    We use Guest with mac caching which creates Known endpoints that are expected to be cleaned up with the Known Endpoints cleanup interval. The interval is based on when the endpoint was last modified.

     

    Since we currently use Endpoints for registered mac address authentication, we cannot use that cleanup option. We periodically run a script that uses the REST API to cleanup any guest endpoints that no longer have a corresponding guest account.



  • 5.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 26, 2018 02:24 PM

    I believe that, by defalt, the cleanup runs at 1 AM daily.



  • 6.  RE: CPPM Endpoint Cleanup

    Posted Feb 26, 2018 02:26 PM

    I wanted to start with just unknown endpoints. I set that to 7 days and I still have items which are over 7 days old listed in the endpoint database.

     

    I am also using MAC caching for guests. So I have to be careful with the known endpoint cleanup. 

     

    Here is how I have it set currently.

     

    Capture.JPG

     

     



  • 7.  RE: CPPM Endpoint Cleanup

    Posted Feb 26, 2018 02:27 PM

    Just to clarify I have had it set for several weeks because I figured the job was not running constantly and had a start point.



  • 8.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 26, 2018 02:30 PM

    With Unknown Endpoint cleanup set to 7 days I would expect endpoints at up to 8 days since the cleanup only runs once a day.

    The endpoints that would normally expire between intervals get caught at the next cleanup.



  • 9.  RE: CPPM Endpoint Cleanup

    Posted Feb 26, 2018 02:43 PM

    Thats what I figured. I will just monitor it tonight. I am not sure what caused the accepted solution to take place. 

     

    Thanks,

    Chris



  • 10.  RE: CPPM Endpoint Cleanup
    Best Answer

    MVP
    Posted Feb 26, 2018 02:46 PM

    You probably missed the Reply button & hit Accept as Solution.



  • 11.  RE: CPPM Endpoint Cleanup

    Posted Feb 27, 2018 07:05 AM

    Yea sorry about that. After watching last night. I did not see any cleanup processes take place around 1AM. Maybe I am missing something to kick those off or a service is not running. 

     

    Weird.



  • 12.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 27, 2018 07:34 AM

    Under "Administration -> Server Manager -> Local Shared Folders -> Backup files" do you see anything? My files are dated around 1:30AM

     

    I assumed the cleanup jobs run about the same time. It would make sense to clean up before backing up.

     

    Perhaps a call to TAC would help resolve this. If they do ot know they can verify with Engineering.



  • 13.  RE: CPPM Endpoint Cleanup

    Posted Feb 27, 2018 08:01 AM

    Yea I definely don't have anything listed in automated backup files either. I only see stuff that I have kicked off in the backup files folder.

     

    Let me check with TAC.

     

    Thanks,

    Chris



  • 14.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 27, 2018 08:04 AM

    It sounds like you have something amiss.

    I generally include my Aruba SE on any TAC emails so they are informed of the situation too. Sometimes they can use other resources to release a logjam.



  • 15.  RE: CPPM Endpoint Cleanup

    MVP
    Posted Feb 27, 2018 08:14 AM

    Check "Administration -> Sertver Manager -> Server Configuration -> Cluster-Wide Parameters -> Database -> Auto backup configuration options". Mine is set to "Config|Session" but there is an Off option. Default is Config.



  • 16.  RE: CPPM Endpoint Cleanup

    Posted Feb 27, 2018 08:25 AM

    Mine was set to config. I set it to Off and Saved it. Then I set it to Config|Session. I will put a case in anyhow and see what they say. Will monitor.

     

    Thanks,

    Chris