Avatar of cweldoncd
cweldoncd

asked on 

MS Operations Manager - SCOM Audit Database uncontrolled growth

our SCOM Audit Database just grows and grows. How can we use the product to groom its own data automatically?  
Microsoft ApplicationsMicrosoft Legacy OS

Avatar of undefined
Last Comment
cweldoncd
Avatar of jss1199
jss1199

Hello cweldoncd,

Are you speaking of the Audit Collection database (ACS)?  Ensure you have applied the hotfix noted in http://support.microsoft.com/kb/949969.  This was a common issue just fixed last month.

Also, read SecureVantage's blog - especially thier entries on ACS Partition grooming -http://securevantage.spaces.live.com/blog/cns!905E136EE69247B4!214.entry  They also provide free filters and analysis, I beleive, to discard some of the security event noise.

Regards,

jss1199
Avatar of cweldoncd
cweldoncd

ASKER

using the second link provided we were able to the Check Partition Groom cycle configuration in Days and it was set to 8. when we checked the number of partition Ids in the dtPartition table we had 90 with a status of 1. we ran the update statement and now watching to see if it will groom itself. after the grooming we plan to install the KB from the first link.  I will post results.

 
Avatar of jss1199
jss1199

Great.  This is common if you are using  SQL Standard - SQL Enterprise allows for online indexing so the jobs have all the time they need to finsh - but you pay much $$$ for this.  We have nearly 2 TB of ACS data, so I feel your pain.
Avatar of cweldoncd
cweldoncd

ASKER

Ok, we waited overnight for the 91 rows to be brought down to the 8 we have the application set to....no luck.  Do I need to adjust anything else?  I ran the

SELECT * FROM [dbo].[dtPartition]

and it returned the 91 rows, all with a status of 2. However, there is 1 row that has a status of 0.
Avatar of jss1199
jss1199

Go into the dtConfig on the AC Database and ensure the # of partitions that you want is correct.  Then restart the Collector service.

Those with a status of 2 will be groomed, but it can take from a few hours to days depending on the amount of data, whether you are SQL standard/Enterprise, and the performance of your server.  You are past the largest hurdle - ensuring your partitions are in a state to be groomed (2)
Avatar of cweldoncd
cweldoncd

ASKER

Ok, thanks! This worked great! We went from 24GB down to 800MB!  After things settle, we may increase this to 14 days.

One last question, does the OperationManagerDW have anything to do with the data from the ACS database.  It seems like when I turned on the ACS function all those many months ago, this database grew a lot.  The OperationManagerDW size is 17 GB w/ only 600 mb of free space if we were to shrink it.  
ASKER CERTIFIED SOLUTION
Avatar of jss1199
jss1199

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of cweldoncd
cweldoncd

ASKER

Thanks for all the help! Awesome knowledge here....
Microsoft Legacy OS
Microsoft Legacy OS

The Microsoft Legacy Operating System topic includes legacy versions of Microsoft operating systems prior to Windows 2000: All versions of MS-DOS and other versions developed for specific manufacturers and Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions, and Windows Mobile.

55K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo