<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Handling Log Exporter in Management HA with dual &amp;quot;Primary&amp;quot; log servers. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Handling-Log-Exporter-in-Management-HA-with-dual-quot-Primary/m-p/275585#M104968</link>
    <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;Setup: Management server in HA, Hardware: open server, OS: R82.10.&lt;/P&gt;&lt;P&gt;I have a Management HA setup where both servers are configured as Primary Log Servers (Gateways are sending logs to both simultaneously). I've configured Log Exporter on Mgmt1 to forward to our SIEM, and it’s working fine.&lt;/P&gt;&lt;P&gt;The issue is failover. Our SIEM does not support deduplication, so I can't run the exporter on both management servers at the same time without doubling our data. The client also wants to keep the dual-primary logging config, so I can't switch to a Primary/Secondary log server hierarchy.&lt;/P&gt;&lt;P&gt;Is there a standard way to automate an "Active/Standby" behavior for the Log Exporter process? I'm looking for a way to have the exporter start on Mgmt2 only if Mgmt1 goes down, without manual CLI work.&lt;/P&gt;&lt;P&gt;Any scripts or best practices for tying cp_log_export to the HA state?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9282" target="_blank" rel="noopener"&gt;@Magnus-Holmberg&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213" target="_blank" rel="noopener"&gt;@the_rock&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2026 06:42:31 GMT</pubDate>
    <dc:creator>sandeepsutar</dc:creator>
    <dc:date>2026-04-16T06:42:31Z</dc:date>
    <item>
      <title>Handling Log Exporter in Management HA with dual "Primary" log servers.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Handling-Log-Exporter-in-Management-HA-with-dual-quot-Primary/m-p/275585#M104968</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;Setup: Management server in HA, Hardware: open server, OS: R82.10.&lt;/P&gt;&lt;P&gt;I have a Management HA setup where both servers are configured as Primary Log Servers (Gateways are sending logs to both simultaneously). I've configured Log Exporter on Mgmt1 to forward to our SIEM, and it’s working fine.&lt;/P&gt;&lt;P&gt;The issue is failover. Our SIEM does not support deduplication, so I can't run the exporter on both management servers at the same time without doubling our data. The client also wants to keep the dual-primary logging config, so I can't switch to a Primary/Secondary log server hierarchy.&lt;/P&gt;&lt;P&gt;Is there a standard way to automate an "Active/Standby" behavior for the Log Exporter process? I'm looking for a way to have the exporter start on Mgmt2 only if Mgmt1 goes down, without manual CLI work.&lt;/P&gt;&lt;P&gt;Any scripts or best practices for tying cp_log_export to the HA state?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9282" target="_blank" rel="noopener"&gt;@Magnus-Holmberg&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213" target="_blank" rel="noopener"&gt;@the_rock&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 06:42:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Handling-Log-Exporter-in-Management-HA-with-dual-quot-Primary/m-p/275585#M104968</guid>
      <dc:creator>sandeepsutar</dc:creator>
      <dc:date>2026-04-16T06:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Handling Log Exporter in Management HA with dual "Primary" log servers.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Handling-Log-Exporter-in-Management-HA-with-dual-quot-Primary/m-p/275589#M104970</link>
      <description>&lt;P&gt;There's no standard way to automate this, it would require external monitoring of something and thus the external tool starting and stopping log exporter on the standby mgmt server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the customer has their gateways configured to forward logs to the primary mgmt server at midnight (will be the default for new gateways created in R82.10 mgmt servers onwards) then the logs will all end up at the SIEM eventually, after the local logs that spool up on the gateways while the server is down are picked up and sent over. Else the recommended solution would be log distribution and a SIEM connection to both mgmt servers, but then the customer loses the duplication of logs at the log servers.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 07:57:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Handling-Log-Exporter-in-Management-HA-with-dual-quot-Primary/m-p/275589#M104970</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-16T07:57:08Z</dc:date>
    </item>
  </channel>
</rss>

