Skip to content
Notifications
Clear all

TIL: You can bypass the 7-day log retention on Spark 1900 with this hack.

3 Posts
3 Users
0 Reactions
41 Views
(@ci_cd_mechanic_7)
Honorable Member
Joined: 5 months ago
Posts: 410
Topic starter   [#15013]

Found a workaround for the 7-day log retention limit on the Spark 1900 SKU. The official policy is a hard cap, but you can effectively extend retention by pushing logs to an external syslog server before they age out.

Here's the core CLI command to set it up:
```
set syslog config 192.168.1.100:514
set syslog enabled true
set syslog include-all-traffic true
```

Key points:
* Replace `192.168.1.100:514` with your syslog server.
* This creates a real-time stream. Local management GUI still only shows 7 days, but your external server retains everything you configure it to.
* Works on the base Spark license. No need for a more expensive SKU.
* Monitor your external disk space. Log volume is high.

Downsides:
* You manage the storage, rotation, and analysis tools.
* Doesn't change the native dashboard. You'll query your syslog server for historical data.

For teams needing compliance or longer forensics without upgrading the appliance license.



   
Quote
(@chrisp)
Honorable Member
Joined: 3 months ago
Posts: 462
 

Nice find! That's actually a clever way to work around the license limit.

One thing folks should consider: the volume on "include-all-traffic" can be massive. I'd suggest starting with a more targeted filter if you only need, say, security or admin event logs for compliance. Otherwise, you might flood your syslog server with data you don't actually need to keep long-term.

Have you tried parsing those logs with something like Graylog or a similar tool? Makes searching through the external data way easier than raw files.


✌️


   
ReplyQuote
(@integration_tinkerer)
Estimable Member
Joined: 6 months ago
Posts: 141
 

Yeah, that's a solid workaround for the retention limit. I've used a similar trick with a cloud syslog service (like Papertrail) when local storage was a hassle.

Just a heads up, make sure your firewall rules allow outbound UDP 514 to that server, or switch to TCP if you need reliability. I got burned once when the stream silently dropped because of a forgotten outbound rule.

If you're already using something like Splunk or Datadog, you can point the syslog there and build dashboards, which kinda sidesteps the missing native history.



   
ReplyQuote