The ccg.log truncates on a regular bases, unless the debugging for the cluster is turned on.
One way to see what might be overwhelming the logs is to use a command similar to this, which can give you a count of entries per source (substitute source name for each connected source):
I like to pipe the output to less -R so that I can easily move up and down, using forward and reverse search. The more specificity you put into the timestamp (i.e., to the hour, to the minute…) you will reduce the number of log entries to review.
Thanks so much for getting back to me; I really appreciate it. I’ll give your suggestion a try.
Quick question: could this issue be related to a change I made last month?
On August 12, 2025, SailPoint Support asked me to update the logger settings specific to Okta using the following documentation: Enable Connector Logging