When you run the Solr script, older alerts and other events for the required number of days are imported into Solr. You specify the required number of days when you run the script for Apache Solr.
Note
The steps outlined below for running the Apache Solr scripts are applicable to Manager version 9.1.7.77 till 10.1.7.40 only. For more detailed information on synchronizing IPS alerts in the Solr Database, refer to KB86158.
Task
- Log in to the Manager shell.
- Stop the Manager service using the manager stop command.
- Stop the Apache Solr service using the solr stop command.
-
Execute the following command block to run the solrImport.sh script:
When you run the Solr script, older alerts and other events for the required number of days are imported into Solr. You specify the required number of days when you run the script for Apache Solr. For example, solrImport offline start days=25, imports 25 days of data. But assume there are 15 million alerts in the database. In that case, 5 million of the oldest alerts are deleted.run solrImport.sh offline start days=<number of days of data you want to import into Solr> -
Wait for the batch file to complete and then start the Apache Solr service using the
solr start command and the Manager service using the
manager start command.
Note
After you restart, once the Manager comes up, go to Manager → <Admin Domain Name> → Maintenance → Database Pruning → Alert Pruning. Set the Maximum Alerts to Store for Dashboard Data to maximum intended alert limit and save. The Manager uses MariaDB which has a pre-defined alert capacity of 30,000,000 alerts. In addition, the Manager uses an open-source search application called Solr, which stores alerts within a flat file. If the Manager server has 8 GB of RAM, it supports 3 million alerts in the Solr database. If the Manager server has 16 GB or more of RAM, it supports 10 million alerts in the Solr Database