Technical Tip: Use the CLI to bulk delete EventDB events from the database to free up space
| Description | This article describes how to delete events in mass from the EventDB database to free up space and purge old and unnecessary data. |
| Scope | FortiSIEM. |
| Solution | To manually delete the outdated data from the event database, remove all files that are older than X days.
Before deleting anything, use this command to check what will be deleted:
For example, to remove all the data and events older than 150 days, run the following:
find /data/eventdb/ -type f -mtime +150 -name '*' -exec rm -rfv {} \; Note: This example illustrates the removal of data that is 150 days old. This number can be adjusted based on specific requirements.
For more information related to space purging, see the 'Retention Policies' documentation: |
