Continuing a thread from teh old boards. I have been having slow connection to the PM10 server. The PMC is on the same network as the server. all gig connectiuons. one thing I noticed was the abiity to delete alerts was taken away. I then question why you would acknowledge an lert that will be displayed until the alert view (mine set to 30) passes???? anyway I got a process that if you mess it up will break your database from tech support on how to delete the alerts from the database. I find the whole procedure unacceptable. Why go through all of this. It is thier suggestion that my loading up and use of PM10 may be slow because I have 1000 alerts that I can't get rid of under the alerts tab. Here is the procedure from the email they sent me. I think it is ridiculas that they would advise such a thing. I can't tell you how many times I will get a system that throws out hundreds if not thousands of alerts because F-Secure can't deal with a malware that keeps respawining it self or I get the "no scanners available" a couple thousand times filling up the log. I am a small shop with 5500 desktops. I can't live oin the policy manager and monitor it all day. And don't get me started on how bad the anti malware / spyware product is. It is useless. More often than not I use the free Malwarebytes program to clean a system the F-Secure let get infected and then can't remove the proble. Malwarebytes is almost always 99 percent succsseful. I only bring up the maleware issue because often my alerts are full of alerts about spyware the F-Secure could not deal with.
Dear John,
Thank you for contacting F-Secure.
It might be the increasing amount of alerts are causing the slowness. The only way to remove alerts in Policy Manager 10 is delete them directly from H2 database, however the following steps are for your reference only, we are not responsible for any unwanted SQL actions done in the H2 Database:
To get access to the H2 Database Console you have to:
Enable H2 Database Console - set 'h2ConsoleEnabled' java property to 'true'
-------------------------------------------------------------------------------------------
To Do this:
-Stop poliy manager server service
-Open registry and Proceed to HKEY_LOCAL_MACHINE\SOFTWARE\Data Fellows\F-Secure\Management Server 5
-Include -Dh2ConsoleEnabled=true in the value data for additional_java_args
-Restart F-Secure Policy Manager Server service for the change to be taking effect
-Done
Click on a shortcut to the H2 Database Console on a Policy Manager Server welcome page.
------------------------------------------------------------------------------------------------------------
To Do this:
Go to start--policy manager--status monitor. Check your administration module port number. The default is 8080.
Example on the browser go to 192.168.54.132:8080 and hit enter. You should able to see a link called "H2 Console". Click on that link and will take you the H2 Database Console.
To Delete the Alerts
------------------------
You need to use the SQL delete the entry. You can just copy and paste the below command and click on "Run Ctrl+Enter" button :
-----------------------------------------------------------------------------------------------------------------------------------------
you can create a script to move the alerts to a temporary location then delete the alerts:
CALL CSVWRITE ('c:/temp/alerts.csv', 'SELECT oid, severity, time, message_params, non_localized_message, host_identity, user_name, trap_count, ack FROM alerts JOIN oid_dictionary ON oid_dictionary.id = alerts.oid_id JOIN domain_tree ON domain_tree.id = alerts.domain_id', 'UTF-8', ';');
DELETE FROM alerts;
To delete the alerts here's the command:
DELETE FROM alerts;