cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 1 of 33

SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

We are using ePO 5.9.1. Over the past week, I have noticed that the SQL database for ePO has been growing about 1GB per day. This is very unusal for us as it usually stays about 5GB. The only thing that we have done is to deploy ePO Agent 5.6.0.878 to all our 2,000 endpoints. Is it possible that this agent is causing events to be sent back to ePO thus filling up to database.

 

I have tried some queries of the database that look for top event ids, but done see anything too large. Not too sure what is going on. Any suggestions?

Also, we arenoty using DXL/TIE and I know that this new agent deploys a DXL component to the endpoints

1 Solution

Accepted Solutions
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 15 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

ePOProductEventsMT contains client events ... the table EPOEvents contains Threat Events. Revisit the sql command - instead of searching for threats reverse engineer for clients events ... or Best practice: Create client event summary queries : display events sent from your agents to McAfee ePO, create client event summary queries - https://docs.mcafee.com/bundle/epolicy-orchestrator-5.9.0-product-guide/page/GUID-F14501EF-EF6D-483A...

Due to the large number you may want to start small and build up - suggest running query for only 15 minutes

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers

View solution in original post

32 Replies
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

You may already have set this up - still worth asking - are you following: Maintaining the McAfee ePO SQL database best practice

Perform these tasks regularly to maintain your SQL Server:

  • Regularly back up the McAfee ePO SQL database and its transaction log.
  • Reindex your database regularly.
  • Rebuild your database regularly.
  • Purge older events using server tasks.

https://docs.mcafee.com/bundle/epolicy-orchestrator-5.9.0-product-guide/page/GUID-B2F573B4-EDE4-4C9E...

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

Yes, I do purge the database weekly. The database is backed up with a disaster recovery snapshot on a daily basis at about 3am. 

The database is reindexed once a day and rebuilt once a week. The only thing that has changed is deploying ePO agent 5.6.0.878 to all our endpoints. 

 

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

What version were you on before 5.6.0.878? 

I've used this in the past and found it to be very useful - How to identify why the ePolicy Orchestrator database is very large : https://kc.mcafee.com/corporate/index?page=content&id=KB76720

 

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 5 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

The agent we were on before 5.6.0.878 was version 5.5.1.388. 

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 6 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

toptables.pngTopevents.png

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 7 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

Foudn this post - worth reviewing:

The tablenames changed from EPO 5 to 5.X and may have changed in EPO 10.

OLD: EPOProductEvents

NEW:EPOProductEventsMT

https://community.mcafee.com/t5/ePolicy-Orchestrator/How-to-Purge-ePO-events-in-the-DB/td-p/492281

 

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 8 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

New feature but ....

Code consolidation and merging of management client components — McAfee Agent 5.5.2 or later replaces the Product Improvement Program (PIP) with a new, more efficient, and more secure producttelemetry framework ... https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/28000/PD28068/en_US/...

Running the sql command found in KB76720 may help in understaing what's causing the up tick

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 9 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

Is there a way of stopping this as can't deal with database growth of 1GB per day. I will take a look at the other document, But you can see that we don't have a lot under top events, so not too sure what we need to purge. 

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 10 of 33

Re: SQL database is growing 1GB per day since we deployed Agent 5.6.0.878 from ePO

Jump to solution

Just created a server task that will purge from the last 90 days. I will see if that helps. Is the new way that they are coding creating extra events in the database. If this keeps growing then I may have to make a service call next week.

Thanks for all your suggestions. 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community