When you run the Solr script, older alerts and other events for the required number of days are imported into Solr. You specify the required number of days when you run the script for Apache Solr.
Note
The steps outlined below for running the Apache Solr scripts are applicable to Manager version 9.1.7.77 till 10.1.7.40 only. For more detailed information on synchronizing IPS alerts in the Solr Database, refer to KB86158.
Task
- Make sure that you have stopped the Manager service.
-
In the Manager server, open Windows Explorer and go to
<Manager_Install_Dir>\Solr\server\solr\alerts and
<Manager_Install_Dir>\Solr\server\solr\appAlerts. Delete, rename, or remove the folder named
data.
This step is important because alerts in the old schema cannot be merged with alerts in the new schema. So, the when the folder is recreated, all alerts are in the new schema.
- In the Manager server, open the Windows command prompt and go to <Manager_Install_Dir>\App\bin.
-
Run
solrImport offline start days=<number of days of data you want to import into Solr>
solrImport offline start days=25 imports 25 days of data. But assume there are 15 million alerts in the database. In that case, 5 million of the oldest alerts are deleted.Note
If you have more than 10 million alerts in the Solr database, the oldest alerts are deleted.
-
Wait for the batch file to complete and then start the Manager service.
Note
After you restart, once the Manager comes up, go to Manager → <Admin Domain Name> → Maintenance → Database Pruning → Alert Pruning. Set the Maximum Alerts to Store in Solr Database (Dashboard Data) and Maximum Alerts to Store in Manager Database (Report Data) to maximum intended alert limit and save. The Manager uses MariaDB which has a pre-defined alert capacity of 30,000,000 alerts. In addition, the Manager uses an open-source search application called Solr, which stores alerts within a flat file. If the Manager server has 16 GB or 32 GB of RAM, it supports 10 million alerts in the Solr Database.