<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs and Export  in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27816#M3436</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pretty sure SmartEvent isn't required for exporting across multiple log files, but Log Indexing must be enabled on your management/log server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70779_03FCE038-DA14-4FA6-A4FA-401E22976FE8.jpeg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what management version are you using?&lt;/P&gt;&lt;P&gt;What data is missing from the CSV?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Sep 2018 23:56:01 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-20T23:56:01Z</dc:date>
    <item>
      <title>Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27813#M3433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even after enabling SmartEvent, we are not getting the logs for moredays say last month or so. It simply says no logs found but when we select the log file it is showing all the logs. However, if we select the log file then for sure it will not be of last month. What should be done in order to get the logs of a particular rule/src/dst/port of last month or so without selecting the log file and when we export the file in csv format it only exports the ones which are visible but we want all of them.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2018 07:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27813#M3433</guid>
      <dc:creator>Mohammed_Omin_B</dc:creator>
      <dc:date>2018-09-19T07:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27814#M3434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a thread that addresses the export issue. &lt;A href="https://community.checkpoint.com/thread/8991-how-to-export-all-result-for-the-smartlog-query-shows" target="_blank"&gt;https://community.checkpoint.com/thread/8991-how-to-export-all-result-for-the-smartlog-query-shows&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27814#M3434</guid>
      <dc:creator>Clifton_Watts</dc:creator>
      <dc:date>2019-06-21T09:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27815#M3435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;I tried it in SmartView but there are two issues now. First, is that sometimes its showing the logs for a particular rule/src/dst/port and sometimes says "No records found" and the other one is that while exporting the file, its size is in KBs say 111KB and opening it in .csv results in data loss. I am expecting the log file at least in MBs as there has to be huge traffic flowing in there.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2018 06:04:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27815#M3435</guid>
      <dc:creator>Mohammed_Omin_B</dc:creator>
      <dc:date>2018-09-20T06:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27816#M3436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pretty sure SmartEvent isn't required for exporting across multiple log files, but Log Indexing must be enabled on your management/log server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70779_03FCE038-DA14-4FA6-A4FA-401E22976FE8.jpeg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what management version are you using?&lt;/P&gt;&lt;P&gt;What data is missing from the CSV?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2018 23:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27816#M3436</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-20T23:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27817#M3437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, the requirement was to export all possible logs in one shot along with the Events/ reports generation and found that it can be done with &lt;A href="https://mgmt"&gt;https://mgmt&lt;/A&gt;&amp;nbsp;server IP/smartview. when we opened it, it was saying SmartEvent need to be enabled to view it. And after that it all started with different issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;last time when we enabled log indexing, mgmt server got hanged and was too slow. So this time, we haven't enabled it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mgmt version: R80.10&lt;/P&gt;&lt;P&gt;while opening the .csv file, its empty and looks like it is getting corrupted or data loss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some details which might help -&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;Symptoms:&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;============&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;Logs are Missing per rule&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;Steps Taken:&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;============&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-Rule wise logs unable to generate the .csv file is getting crash&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-While login to Security Policy-&amp;gt;Logs-&amp;gt;unable to see the logs intermittently.&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;Getting the error "no logs" .&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-Mohammed confirmed that when generated log report from Smart View -&amp;gt;logs are missing and also informed that in legecy smart tracker some of the rule logs are missing.&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-#cpwd_admin list -all process are UP and running .&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-Having enough disk space and memory verified #df -kh and free -m&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-Its listening on port 257 verified #netstat -nap | grep 257&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-#tcpdump -nnei any host &amp;lt;Firewall IP&amp;gt; and port 257&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;Firewall is sending logs to Management Server.&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-#cpinfo -y all jumbo_take_112 installed on the appliance.&lt;/SPAN&gt;&lt;BR style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;" /&gt;&lt;SPAN style="color: #252424; background-color: #e0e0ed; font-weight: normal; font-size: 12px;"&gt;-#watch -d -n 2 "ls -l $FWDIR/log/fw.log" show the logs are storing on Management Server.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 07:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27817#M3437</guid>
      <dc:creator>Mohammed_Omin_B</dc:creator>
      <dc:date>2018-09-21T07:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27818#M3438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way you can work with log data that spans multiple log files is to have Log Indexing enabled.&lt;/P&gt;&lt;P&gt;What hardware are you running your management server on?&amp;nbsp;How much memory installed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 13:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27818#M3438</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-21T13:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27819#M3439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its deployed in cloud with 8 core Processor 16GB RAM.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 14:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27819#M3439</guid>
      <dc:creator>Mohammed_Omin_B</dc:creator>
      <dc:date>2018-09-21T14:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs and Export</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27820#M3440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What "cloud" are you deployed in?&lt;/P&gt;&lt;P&gt;Allocating more RAM might be a good idea.&lt;/P&gt;&lt;P&gt;Disk I/O in the cloud may also be a blocking factor as well.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 14:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Logs-and-Export/m-p/27820#M3440</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-21T14:47:44Z</dc:date>
    </item>
  </channel>
</rss>

