Just hit a storage wall with our Sophos XGS 2300's logging. The internal disk was 95% full, mostly from firewall logs going back over a year. Support's immediate suggestion was, of course, "add a storage license." But before we spent on more GBs, I wondered: do we really need logs from 2022 for a compliance window that's only 90 days?
Turns out, the built-in log maintenance is a bit blunt. I wanted something more surgical—keeping all threat/IPS/WAF logs forever (archived to our S3 bucket), but aggressively purging the basic firewall/flow logs after 90 days.
Couldn't find a clean built-in way, so I wrote a script that uses the SFTP backup method. It runs weekly via cron and does this:
* Connects to the XGS SFTP backup location.
* Identifies firewall log files (`fwlog*.tar.gz`) older than our threshold.
* Moves those files to a temporary holding folder.
* Deletes them from the appliance, then cleans up.
The result? Freed up 68GB instantly. The script is lightweight and only deals with the rotated archive files, so zero risk to the active database.
Key configuration bits on the XGS side:
* Logging > Log Settings: Set "Log file backup frequency" to Daily.
* Logging > Backup: Enable SFTP backup to a dedicated path.
* (Crucial) Under each log category (Firewall, Threat, etc.), set the "Send to Backup" checkbox appropriately. For us, only Firewall/Flow are *not* sent to backup, as we purge them.
This approach keeps our critical security logs forever in S3 (via the backup), while ensuring the appliance itself doesn't choke on ancient flow data. Saved us from buying the storage license upgrade, at least for another year.
Has anyone else tackled this differently? I'm curious if there's a more elegant method using the built-in SQL database cleanup commands, but I was hesitant to touch the live DB directly.
That's a solid workaround, and I respect the initiative. But you've just highlighted the exact vendor strategy I can't stand.
They sell you a "solution" that predictably hits a resource ceiling, and the first answer is always an upsell to more licensed capacity. Not a conversation about efficient data lifecycle management, just a higher recurring cost. Your script basically fixes their intentional product gap.
My question is, what's your long-term backup for this? Scripts break, cron jobs get wiped after firmware updates, and you're now the sole owner of a critical compliance function. If you leave, does the next guy even know this fragile pipeline exists? The real cost isn't just the storage license, it's the operational debt you're taking on.
Show me the TCO.