Cleans older pcap artifacts from the alert EBC pcap directory.
Use the retain parameter to configure the retention period, if required.
Use the force parameter to schedule a regular automated cleanup.
On using this CLI, you will receive a request to confirm the amount of data that will be deleted. Once you confirm, the mentioned data will be deleted.
Note
The pcap artifacts, once deleted, can never be restored.
Syntax
bottracker ebc cleanup
bottracker ebc cleanup retain <numberOfDays> days
Note
User confirmation is not required for scheduling an automated cleanup using the
forceparameter.
bottracker ebc cleanup force
bottracker ebc cleanup retain <numberOfDays> days force
Parameters
<numberOfDays>
Enter the number of days of which the pcap artifacts should be retained. You can select the number of days from a set (7/30/180/365). Values greater than a year are invalid.
Examples
The following example cleans all older pcap artifacts from the alert EBC pcap directory.
hostname (config) # bottracker ebc cleanup Proceeding will remove 10.20MB of pcaps permanently Please confirm by typing (yes/no): yes Operation was successful. Bottracker EBC pcap directories for bott cleaned up successfully. Retained pcaps of last 0 days.
The following example cleans older pcap artifacts from the alert EBC pcap directory and retains artifacts from the last 30 days.
hostname (config) # bottracker ebc cleanup retain 30 days Proceeding will remove 20.20MB of pcaps permanently Please confirm by typing (yes/no): yes Operation was successful. Bottracker EBC pcap directories for bott cleaned up successfully. Retained pcaps of last 30 days.
The following example schedules a regular automated cleanup of older pcap artifacts from the alert EBC pcap directory and retains artifacts from the last 30 days.
Note
User confirmation is not required for scheduling an automated cleanup using the
forceparameter.
hostname (config) # bottracker ebc cleanup retain 30 days force Operation was successful. Bottracker EBC pcap directories for bott cleaned up successfully. Retained pcaps of last 30 days.
User role
Administrator or analyst or operator
Command mode
Configuration
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 11.0.0