<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Logging Issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125901#M18275</link>
    <description>&lt;P&gt;There is a trick I learned with logging issues that worked every single time I tried it...so this is what you do:&lt;/P&gt;
&lt;P&gt;-in dashboard, create new CP host (NOT regular host), but under new -&amp;gt; network object -&amp;gt; gateways and servers -&amp;gt; Check Point host&lt;/P&gt;
&lt;P&gt;-give it SAME ip address as your actual management and under management tab, ONLY select logs and servers&lt;/P&gt;
&lt;P&gt;-once you save this object, publish changes and install database on actual management&lt;/P&gt;
&lt;P&gt;-after this, go to your firewall object, and under logs, you should see an option to add this new object you created, just add it and remove existing management object and push policy&lt;/P&gt;
&lt;P&gt;Now, here is the trick...if this works, then I would say maybe leave it like that over the weekend or few days and see what results are. If you see all works fine, then you can remove that object from log section on the gateway and add back regulat mgmt server. I really cant guarantee you 100% it will work, but I must have tried this more than 30 times in the past with people and worked every single time, never failed.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Aug 2021 18:11:19 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-08-06T18:11:19Z</dc:date>
    <item>
      <title>Checkpoint Logging Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125881#M18269</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an ongoing issue where firewall randomly lose connectivity to the log server and starts logging locally.&lt;BR /&gt;For making missing logs viewable on the console follow below action:-&lt;BR /&gt;&amp;gt; Copy missing file (fw.log) and paste it on log server directory post renaming&amp;lt;missingfile1.log&amp;gt;&lt;BR /&gt;&amp;gt; run fw logrepair command, which re-creates all associated pointers and could view files on smart console file package.&lt;/P&gt;&lt;P&gt;The thing is that I would like to see these imported logs also with other logs in smart console, without the need of looking for a particular log package/file.&lt;/P&gt;&lt;P&gt;i.e imported logs should get index and we could see results running general query.&lt;BR /&gt;Can you please advise if there is such possibility to import missing logs from the gateways via CLI, so that they are visible together with other logs in SmartConsole?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint OS R80.30, running recommended Take.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 13:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125881#M18269</guid>
      <dc:creator>dumbhead123</dc:creator>
      <dc:date>2021-08-06T13:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Logging Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125896#M18273</link>
      <description>&lt;P&gt;You can only index logs a number of days back.&lt;BR /&gt;You can’t, to my knowledge, index a specific log file.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/SmartLog-only-look-back-14-days-how-to-reindex-90-days-back/td-p/23280" target="_blank"&gt;https://community.checkpoint.com/t5/Management/SmartLog-only-look-back-14-days-how-to-reindex-90-days-back/td-p/23280&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 16:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125896#M18273</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-06T16:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Logging Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125901#M18275</link>
      <description>&lt;P&gt;There is a trick I learned with logging issues that worked every single time I tried it...so this is what you do:&lt;/P&gt;
&lt;P&gt;-in dashboard, create new CP host (NOT regular host), but under new -&amp;gt; network object -&amp;gt; gateways and servers -&amp;gt; Check Point host&lt;/P&gt;
&lt;P&gt;-give it SAME ip address as your actual management and under management tab, ONLY select logs and servers&lt;/P&gt;
&lt;P&gt;-once you save this object, publish changes and install database on actual management&lt;/P&gt;
&lt;P&gt;-after this, go to your firewall object, and under logs, you should see an option to add this new object you created, just add it and remove existing management object and push policy&lt;/P&gt;
&lt;P&gt;Now, here is the trick...if this works, then I would say maybe leave it like that over the weekend or few days and see what results are. If you see all works fine, then you can remove that object from log section on the gateway and add back regulat mgmt server. I really cant guarantee you 100% it will work, but I must have tried this more than 30 times in the past with people and worked every single time, never failed.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 18:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125901#M18275</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-06T18:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Logging Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125939#M18284</link>
      <description>&lt;P&gt;The best way to this is to use the "Log Forwarding Settings". In the SmartConsole you can define to which log server and when does it occur.&amp;nbsp; You can set a specific time for log forwarding or every few hours.&lt;/P&gt;
&lt;P&gt;SmartConsole -&amp;gt; Gateways &amp;amp; Servers view -&amp;gt; select your GW (double click) -&amp;gt; Logs -&amp;gt; Additional Logging.&lt;/P&gt;
&lt;P&gt;In there you'll find the settings.&lt;/P&gt;
&lt;P&gt;By using this the gateway will forward all the logs to the log server and the logs will be indexed as defined by that log server (if you run in index mode then configuring log forwarding will ensure all of them will be indexed).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 649px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12908i452D139C0E171450/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2021 07:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125939#M18284</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2021-08-08T07:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Logging Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125994#M18293</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37178"&gt;@Amir_Senn&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;
&lt;P&gt;It's important to emphasize that this setting is indeed recommended and will not duplicate your logs. When it's configured on the gateway/cluster, only logs that were written locally will be forwarded to the log server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason that we have a timeframe is that local logs might accumulate to large numbers in case of disconnections or peaks. Some customers want to make sure that the logs will be uploaded in off-hours.&lt;/P&gt;
&lt;P&gt;** We're also looking at ways to make this (or similar behavior) on-by-default for future versions. That way customers won't forget to configure it.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 05:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Logging-Issue/m-p/125994#M18293</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2021-08-09T05:25:30Z</dc:date>
    </item>
  </channel>
</rss>

