<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Importing the old logs.  in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Importing-the-old-logs/m-p/35898#M2919</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Taken that most times the log file rotation is set on the by midnight timeframe, there would be at least 1 file per day. So when you copy those files over to the new R80 management server you would to set the number of days to the number calculated by:&lt;/P&gt;&lt;P&gt;(todays date) - (first date of imported files)&amp;nbsp;so when you&amp;nbsp;imported files starting at Feb 1st you should use the number 25&lt;/P&gt;&lt;P&gt;It will works it way back from the Feb 25th to Feb 1st, there will be a number of days (since your upgrade) that already have been indexed and they will be skipped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do keep in mind this is a very time consuming job and will not finish the same day when you have many files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Feb 2019 21:57:05 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-02-25T21:57:05Z</dc:date>
    <item>
      <title>Importing the old logs.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Importing-the-old-logs/m-p/35897#M2918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;Hi Guys, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;We have recently upgraded or device from R77.30 to R80, but old logs are not reflecting in our R80 smart console. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;After research we got the article #sk111766. But we are un-sure what to give on the below step. It is asking &lt;CODE&gt;&amp;lt;NUM_OF_DAYS_TO_INDEX&amp;gt;. &lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;Import and index the offline logs from the last XX days:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;[Expert@HostName:0]# cd $INDEXERDIR&lt;/CODE&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt; &lt;CODE&gt;[Expert@HostName:0]# ./log_indexer -days_to_index &lt;SPAN style="color: #ff0000;"&gt;&amp;lt;NUM_OF_DAYS_TO_INDEX&amp;gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;Can anyone help on to what the value should we give hear. And what is this "&amp;lt;NUM_OF_DAYS_TO_INDEX&amp;gt;" mean. &lt;BR /&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;Regards, &lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;CODE&gt;Vengatesh SR&lt;/CODE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2019 18:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Importing-the-old-logs/m-p/35897#M2918</guid>
      <dc:creator>Vengatesh_SR</dc:creator>
      <dc:date>2019-02-25T18:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Importing the old logs.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Importing-the-old-logs/m-p/35898#M2919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Taken that most times the log file rotation is set on the by midnight timeframe, there would be at least 1 file per day. So when you copy those files over to the new R80 management server you would to set the number of days to the number calculated by:&lt;/P&gt;&lt;P&gt;(todays date) - (first date of imported files)&amp;nbsp;so when you&amp;nbsp;imported files starting at Feb 1st you should use the number 25&lt;/P&gt;&lt;P&gt;It will works it way back from the Feb 25th to Feb 1st, there will be a number of days (since your upgrade) that already have been indexed and they will be skipped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do keep in mind this is a very time consuming job and will not finish the same day when you have many files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2019 21:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Importing-the-old-logs/m-p/35898#M2919</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-25T21:57:05Z</dc:date>
    </item>
  </channel>
</rss>

