Flushing logs best practice

jgwatson
Contributor

I am fairly new to JAMF and was having a little look around. All of my log flushing is turned off. Just wondering if I should turn any of these on, and which ones?I have 280 iPads, and about 30 Macs.

What do other people do? Thanks

Logs Flush Logs Older Than
Application Usage Logs

Computer Usage Logs

Policy Logs

Casper Remote Logs

Screen Sharing Logs

Casper Imaging Logs

Computer and Mobile Device Management History

JDS Management History

Computer Inventory Reports

Mobile Device Inventory Reports

6 REPLIES 6

mm2270
Legendary Contributor III

We have all our logs set to flush every 2 weeks, but we have a much larger Mac environment (8700+) so for a smaller environment like yours you may be able to get away with waiting longer between, such as 1 month. Log flushing is important to keeping your JSS running smoothly, so you should set them to something. Just my opinion. But I think JAMF would also recommend setting them to flush at some interval, or at the very least doing a manual flush periodically.

donmontalvo
Esteemed Contributor III

JSS has the option to pipe logs to an existing syslog server. Then you can set JSS to dump logs older than two weeks.

Else, not sure how free this one is:

http://www.solarwinds.com/products/freetools/free-kiwi-syslog-server.aspx

--
https://donmontalvo.com

JeffV
New Contributor III
New Contributor III

I think it all depends on your (legal) requirements on how long you want to keep the log files.(also the size of the environment plays part)
In the end if you need older log files you can always restore a database backup to a dev server and retreive the data.
Imho (and looking at our env 2 wks to max a momth is a good practice

Hope it helps with your decision

donmontalvo
Esteemed Contributor III

Companies that have the obligation to retain logs might already have a syslog server. Pipe your logs to it and the problem goes away. :)

--
https://donmontalvo.com

CasperSally
Valued Contributor II

We have 6500 macs and keep 90 days of logs without issue. Some logs like imaging/vnc we set to not delete (those are infrequent relatively).

cdenesha
Valued Contributor III

I am not managing Macs, just 1000 iPads. I have mine set to one year so I can access the Update Inventory logs (and IP addresses) from the past.

Also, they probably should have gone over this at your JumpStart.

chris