Security

 View Only
  • 1.  Clearpass Endpoint database - cleanup

    Posted Jan 29, 2020 02:25 AM

    Good day,

     

    Is there a way to cleanup the database to say if the endpoint device hasnt connected in like 6 months then delete the enpoint.

     

    This doesnt need to be automated but will be nice to have a filter so i can then delete the endpoints.

     

    Regards

    Sini



  • 2.  RE: Clearpass Endpoint database - cleanup

    Posted Jan 29, 2020 03:04 AM

    Hi,

     

    Do you are go on the Cluster Setings ? there is option about cleanup endpoint



  • 3.  RE: Clearpass Endpoint database - cleanup

    Posted Jan 29, 2020 07:53 AM

    Hi, Thanks for the info, i had a look and there is option to cleanup unknown device after a period of days and with known. i dont want to delete all known but rather if the device hasnt connected in 6months for example.

     

    Regards

    Pieter



  • 4.  RE: Clearpass Endpoint database - cleanup

    Posted Jan 29, 2020 08:07 AM

    You can look with API... but you need how to found the endpoint don't use from 6 month...



  • 5.  RE: Clearpass Endpoint database - cleanup
    Best Answer

    Posted Jan 29, 2020 09:33 AM

     Update cluster wide cleanup interval for historical data.

     

    1.  If Endpoint cleanup interval service parameter is specified (for Known or Unknown), then the 'endpoints' are cleaned up only if they are not profiled (i.e., endpoints don't exist in profile table).
    2.  If the Profiled Unknown endpoints cleanup interval service parameter is specified, the entities from profile table along with endpoints which are marked unknown are cleaned up.
    3.  Disabled endpoints are not cleaned up. To cleanup these administrators have to move them to "Unknown" or manually delete them.
    4.  Known endpoints which are profiled are not cleaned up. Administrators have to take the same step as [3].
    5.  Profiled endpoints with 'static_ip' are not cleaned up (irrespective of Unknown endpoint status).
    6.  If Static IP endpoints cleanup option is set to TRUE, the the profiled endpoints with static IP Addresses are cleaned up.
    7.  If the Profiled Known endpoints cleanup option is set to TRUE then the system cleans up (for the duration mentioned in Known endpoints cleanup interval . This parameter makes sense when Known endpoints cleanup interval is non-zero )

    –Profiled Known endpoints

    –Known endpoints

     

    Since clearpass server does not provide access to DB, it is not possbile to query and delete endpoints which are inactive for certain period. It is a good feature, file request @ https://innovate.arubanetworks.com/