Archiving event logs only archives the first 1000 entries, even though there are more events that should be archived. After that first batch of 1000, all other events are deleted from the active database. This means we are missing a significant number of events in the archive database.
We have verified a processing defect in the archiving and purging code in Active Administrator 8.9 where the first 1000 rows from the AlertLog table are read in each batch pass and then written to the archive database, and any subsequent event batches are not archived and purged from the live database.
Scenario:
If we have 18000 items, it means that we calculated 18 batches of 1000 events to archive the data, do 18 passes archiving the first 1000 items, and then purge all 18000 items. This causes the loss of 17000 events.
Workaround
For now, we recommend disabling any archive jobs to prevent further data loss.
The defect ID to be fixed in an upcoming version of Active Administrator is 617144