Prisma Cloud Compute: Retention data in Collections

Prisma Cloud Compute: Retention data in Collections

6349
Created On 03/12/22 21:25 PM - Last Modified 12/04/24 15:18 PM


Symptom


The symptoms are as follows:
  • The scan results like the ones found at Compute > Monitor > Vulnerabilities/Compliance disappear after sitting for up to 30 days.
  • The audits like the ones found at Compute > Monitor > Events  disappear after reaching a cap limit of the number of audits or the amount of data consumed (whichever limit is hit first).


Environment


  • Prisma Cloud Compute- SaaS
  • Prisma Cloud Compute - Self-hosted version 21.04 and above


Cause


  • Prisma Cloud caps the size of some data collections to prevent misconfigured systems from consuming all available disk space and compromising the availability of the Console service.
  • The retention of data collections on the Compute Console is governed by limitations enforced on the Console's database.


Resolution


Few ways to retain the data collections on and off the Compute Console are as follows:
  1. The "Registry scan results" found at Compute > Manage > System allow you to customize the period of retaining the scan results of images deleted from the registry in the range of 1-30 days.
​​​​​Screen Shot 2022-03-12 at 3.01.06 PM.png
 
  1. For audits, if you must retain all of them, consider configuring Console to send audits to syslog, and then forward audits to a log management system for long-term storage
  2. The scan results can be exported as a CSV file on a regular basis in order to make sure that you do not lose any data.


Additional Information


The links to a few useful and relevant technical documents are as follows:



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNMeCAM&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail