Activity Feed
- Posted Re: Phantom App for Splunk not respecting Global field mappings on Splunk SOAR. 06-27-2022 09:46 AM
- Karma Re: Phantom App for Splunk not respecting Global field mappings for soumyasaha25. 06-27-2022 09:44 AM
- Karma Re: What is the proper way to Purge SOAR containers/events? for phanTom. 06-27-2022 01:39 AM
- Posted Re: Phantom App for Splunk not respecting Global field mappings on Splunk SOAR. 06-27-2022 01:30 AM
- Karma Re: Purge SOAR containers/events for phanTom. 06-22-2022 08:53 AM
- Posted Re: Purge SOAR containers/events on Splunk SOAR. 06-22-2022 08:50 AM
- Posted Re: Purge SOAR containers/events on Splunk SOAR. 06-20-2022 09:04 AM
- Tagged Re: Purge SOAR containers/events on Splunk SOAR. 06-20-2022 09:04 AM
- Posted What is the proper way to purge SOAR containers/events? on Splunk SOAR. 06-20-2022 07:28 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
06-27-2022
01:30 AM
Hello @soumyasaha25 , I am having a similar issue and was wondering if you have figured out the root cause or a fix?
... View more
06-22-2022
08:50 AM
Hello @phanTom, you are right the script works well and the containers data is purged from the database. However, I am noticing that the folder "/phantom/data/db/pg_wal" (45G) is huge compared to "/phantom/data/db/base" (4.5 G). From searchihng in Postgres forums it seems that pg_wal is supposed to be cleaned automatically by postgres ... any ideas on why this is not happening or from where I coud start troubleshooting 🙂 thank you in advance.
... View more
06-20-2022
09:04 AM
Thank you for your reply @phanTom , I have executed this script and deleted approximately 10k containers with the artifacts, playbook runs and action runs associated to them ... However I do not seem to notice any changes on disk Space usage, (by the way my goal of purging containers is to free up some disk space). Is the script deleting the data from the database or should I follow further steps to delete this data from the database?
... View more
- Tags:
- Reply
06-20-2022
07:28 AM
Hello,
What is the proper way to purge Splunk SOAR/phantom containers from the database. It seems that deleting a container only hides it from the UI.
Is there a way to purge containers with certain filters for example purge containers where label="secific_label" and created before 6 months ... ?
... View more
- Tags:
- SOAR
Labels
- Labels:
-
administration