Security

Reply
KDI
Contributor I
Posts: 25
Registered: ‎02-02-2015

Endpoint Cleanup Question

We are investgating the implementation of more rigid clean up intervals in order to reduce our endpoint db.   We are currently running CPPM 6.5.  In our test environment I have worked with all of the available interval settings and believe I understand them all.  That said I am left with a number of unknown endpoints that are not profiled having no attribute.  I dont see a setting where we can remove unknown, non profiled endpoints. We have tested in our testbed; max inactive time for an endpoint, known endpoints cleanup interval, unknown endpoints cleanup interval , profiled unknown endpoints clean up interval,and even played around with the profiled endpoints option set to true. All these settings will produce the desired results but we are still left with "stale" unknown, non profiled endpoints.  Please advise.  Thanks.

KDI
Contributor I
Posts: 25
Registered: ‎02-02-2015

Re: Endpoint Cleanup Question

I self resolved this .  I re investigated settings and set to 7 days.  Stale objects are gone.

New Contributor
Posts: 4
Registered: ‎01-09-2015

Re: Endpoint Cleanup Question

Hi KI,

 

Thanks for reporting back. I'm in a similar situation as you where there are endpoints in a domain we cannot profile but need to purge at some interval.  Since we cannot profile them they never have an "Updated At" attribute.  Which setting did you ultimately wind up tweaking to remove these Unknown Non-Profiled endpoints?  Was it the "Unknown endpoints cleanup interval" under the Cleanup Intervals tab in Cluster-Wide Parameters?  My only confusion with this is that in the documentation it says this is based on the "Updated At" value which non-profiled endpoints do not have.

 

Thanks.

KDI
Contributor I
Posts: 25
Registered: ‎02-02-2015

Re: Endpoint Cleanup Question

JG-

 

I ended up getting aggressive with the value on the parameter 'unknown endpoints clean up' interval setting the value to 7 days.   I had a number of stale devices with no attribute including the one you mentioned. Many were gone the next day.

 

Also I discovered that the parameters 'known endpoint clean up' interval and 'profiled unknown endpoints clean up' interval will not accept a value over 180.  

 

These values are located at Cluster Wide Parameters>Clean up Intervals tab

 

I too struggled with the documentation.  We are fortunate to have a test bed so I interpreted the documentation and tested/monitored in our TB in order to get the correct combination for our environment/configuration.  I am deploying in production next Tuesday.

 

Hope this helps.

KI

Search Airheads
Showing results for 
Search instead for 
Did you mean: