We have an ELM with a DAS. We're being asked by a customer to provide copies of their raw logs (sounds like we might be losing them as clients, ugh) for offline storage, not bound by retention timeframes. Is there a way to copy the raw logs from the DAS? If they provide us with storage device, is it as simple as mirroring the storage pool on another device?
Solved! Go to Solution.
Hello,
The ELM stores raw logs from different data sources which have been assigned to a specific storage pool as compressed .elm files. These files can go upto 2GB in size.
So querying and extracting the raw logs for all the millions of events is a very slow and cumbersome process.
For all the ways on querying and retrieving logs from an ELM, refer the following KB article:
KB82518 How to find and retrieve Enterprise Log Manager data
https://kc.mcafee.com/corporate/index?page=content&id=KB82518&locale=en_US
Hello,
The ELM stores raw logs from different data sources which have been assigned to a specific storage pool as compressed .elm files. These files can go upto 2GB in size.
So querying and extracting the raw logs for all the millions of events is a very slow and cumbersome process.
For all the ways on querying and retrieving logs from an ELM, refer the following KB article:
KB82518 How to find and retrieve Enterprise Log Manager data
https://kc.mcafee.com/corporate/index?page=content&id=KB82518&locale=en_US
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA