<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU usage on management server [r81.10] in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/147744#M73366</link>
    <description>&lt;P&gt;Hi jb1!&lt;/P&gt;&lt;P&gt;Have you got any updates on this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm having a similar problem and I'd like to know if you could share any info that could help.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 03 May 2022 16:16:52 GMT</pubDate>
    <dc:creator>Fernando_Lopez</dc:creator>
    <dc:date>2022-05-03T16:16:52Z</dc:date>
    <item>
      <title>High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/138226#M73358</link>
      <description>&lt;P&gt;We have upgraded from r80.40 to r81.10 some time ago. In the beginning the 100% CPU usage on the management server was expected as it was reformatting the logs for r81.10. Unfortunately we have been getting sporadic spikes in cpu usage causing the recent traffic not to be shown in the console.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our Situation:&lt;/P&gt;&lt;P&gt;2x Open server in HA (active-standby) On premise&lt;/P&gt;&lt;P&gt;2x Azure Checkpoint appliances in HA (active-standby)&lt;/P&gt;&lt;P&gt;1x Security management server 8 vcpu 32 Gb (VmWare)&lt;/P&gt;&lt;P&gt;We have a VPN tunnel between azure and on-premise.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14858iCEC12ECF891C83B3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="checkpoint.PNG" alt="checkpoint.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;top and htop are attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bram&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 10:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/138226#M73358</guid>
      <dc:creator>bramotten</dc:creator>
      <dc:date>2022-01-12T10:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/138263#M73359</link>
      <description>&lt;P&gt;The nice (NI) value shown in top for the CPU-heavy java processes is 19, which means they are set for minimum CPU priority.&amp;nbsp; These are going to be your log_indexder and SOLR processes, which will get kicked off the CPU immediately if some other process needs to use it.&amp;nbsp; There have been several other threads about this and it is expected behavior, if you are having issues with logs not showing up in a timely fashion there could be contention for the hard drive, although your waiting for I/O (wa) is showing as zero.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 13:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/138263#M73359</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-01-12T13:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/142951#M73360</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;did you solve this issue? I currently have two environments with the same symptoms as you with high CPU ussage(after mgmt upgrade to R81.10 CPU is at 90%)&amp;nbsp; Before the upgrade it was 20-30%. In one environment, I observed that the issue was caused by log_exporter, but after a while (2 days) the CPU levels were OK. For some reason, after the upgrade, I see a lot of wa (wait) when running the "top" command on the mgmt server. Like Timothy suggested my first culprit was disk. But after checking the actual disk r/w I can see that there are spikes up to 150M but this should still be OK. Mem is OK, NICs are OK so I don't know what is causing CPU waits in such a number? At the top we have java process with 600%, followed by indexer and exporter at 100% All of them have NI value of 19. What I did noticed is that when wa kicks in java process drops fromm 600 to 100. Then it rises again until there are wa's again...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. before the upgrade everything was working OK, so something changed. Two different environments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br J&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 07:43:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/142951#M73360</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-03-04T07:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/142985#M73361</link>
      <description>&lt;P&gt;If you recently upgraded, make sure that its not “still reindexing your logs” (after upgrade to r81x we reindex all the logs)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 13:44:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/142985#M73361</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2022-03-04T13:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143232#M73362</link>
      <description>&lt;P&gt;Hello Dorit, nice to hear from you. It seems you were right - both systems are now running OK. After your suggestion I did some further investigation and noticed that all the environments that had manually&amp;nbsp; added custom value of&lt;EM&gt;"days_to_index (value)" &lt;/EM&gt;in $INDEXERDIR/log_indexer_custom_settings.conf,&amp;nbsp; prior to upgrade had high CPU issue. And this files survives and upgrade. As stated in &lt;A href="https://community.checkpoint.com/t5/Management/Cannot-view-previous-logs-after-upgrade-to-R81/td-p/117845" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Cannot-view-previous-logs-after-upgrade-to-R81/td-p/117845&lt;/A&gt; R81 should only re-index logs for 24h&amp;nbsp; unless triggered manually - but that is something a reboot does &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What was weird and made me look away from indexing is&amp;nbsp; that the process that was consuming CPU was java, not log_indexer as in previous versions when re-indexing.&lt;/P&gt;&lt;P&gt;Thank you for your response!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 13:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143232#M73362</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-03-08T13:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143292#M73363</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15024"&gt;@cir007&lt;/a&gt;&amp;nbsp;JAVA process that was working hard during reindexing is actually SOLR daemon (you can see it in top -c).&lt;/P&gt;
&lt;P&gt;The default value of Days to Index is 24 hours, I don't know what was the reason to change it prior to upgrade, and usually it is not necessary, but specifically&amp;nbsp;in upgrades from R80.x to R81/R81.x, users might change this value to a longer time. In R81 we upgraded the SOLR indexing engine, and the new engine cannot read from indexes that were created prior the upgrade.&lt;/P&gt;
&lt;P&gt;Now after reindex is completed, I'm sure you notice much faster log queries and reports.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 20:49:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143292#M73363</guid>
      <dc:creator>Miri_Ofir</dc:creator>
      <dc:date>2022-03-08T20:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143462#M73364</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;a OK I can see it now. The reason why this value is/was changed is because of Smarevent reports. At some time the customer wanted to have the ability to create Smart-event reports for 90/180 days. To achieve that disk space was added to the mgmt and logs were imported back to SE and re-index so that the customer could could do reports for more than 14 days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately&amp;nbsp; that did not played out well, after the upgrade to R81 I've noticed that re-index for old logs is not done properly as some chunks of indexed logs are randomly missing. I've deleted the new index files and ran another re-index but&amp;nbsp; the result was almost the same in two environments where the need for Smart-event history is "required" I've contacted TAC on this issue.&lt;/P&gt;&lt;P&gt;Thank you for replay.&lt;/P&gt;&lt;P&gt;Br J&lt;/P&gt;&lt;P&gt;Yes I do have to say, new reports and queries does feel faster, kudos for that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 07:07:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143462#M73364</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-03-11T07:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143600#M73365</link>
      <description>&lt;P&gt;I see. please share with me the SR privately, I will monitor the case with TAC&lt;/P&gt;</description>
      <pubDate>Sun, 13 Mar 2022 19:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/143600#M73365</guid>
      <dc:creator>Miri_Ofir</dc:creator>
      <dc:date>2022-03-13T19:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/147744#M73366</link>
      <description>&lt;P&gt;Hi jb1!&lt;/P&gt;&lt;P&gt;Have you got any updates on this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm having a similar problem and I'd like to know if you could share any info that could help.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 16:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/147744#M73366</guid>
      <dc:creator>Fernando_Lopez</dc:creator>
      <dc:date>2022-05-03T16:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/147795#M73367</link>
      <description>&lt;P&gt;Hello Fernando!&lt;/P&gt;&lt;P&gt;If you are talking about the high CPU than the issue was&amp;nbsp; SOLR daemon re-indexing old files. If you are talking about the problem where some logs were not indexed, then I just, received word from TAC yesterday actually, saying that they found a problem and portfix is available. They also mentioned that this fix will be implement in the next JHF, that will be out in a couple of weeks. In this environment. Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br J&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 05:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/147795#M73367</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-05-04T05:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/149966#M73368</link>
      <description>&lt;P&gt;Hi jb1!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Already solved mine; SMS was stuck trying to reindex log files.&lt;/P&gt;&lt;P&gt;As it was a VMWare machine, I was able to reinstall the SMS entirely and that solved the problem somehow.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 16:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/149966#M73368</guid>
      <dc:creator>Fernando_Lopez</dc:creator>
      <dc:date>2022-06-01T16:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/150218#M73369</link>
      <description>&lt;P&gt;Hello Fernando,&lt;/P&gt;&lt;P&gt;a drastic move &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; were any changes made in the $INDEXERDIR/log_indexer_custom_settings.conf? ,specifically with parameter days_to_index&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 07:02:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/150218#M73369</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-06-06T07:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/156180#M73370</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can we assure that re-indexing is not happening.&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;Shashidhar&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:21:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/156180#M73370</guid>
      <dc:creator>Shira</dc:creator>
      <dc:date>2022-09-01T11:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on management server [r81.10]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/156187#M73371</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;"top -c" look for opt/CPrt-R81.10/log_indexer/log_indexer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CPU usage for this will be close to 100%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;17401 admin 39 19 998408 390944 9488 S &lt;STRONG&gt;14.9&lt;/STRONG&gt; 0.6 2162:40 /opt/CPrt-R81.10/log_indexer/log_indexer&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU-usage-on-management-server-r81-10/m-p/156187#M73371</guid>
      <dc:creator>cir007</dc:creator>
      <dc:date>2022-09-01T11:26:39Z</dc:date>
    </item>
  </channel>
</rss>

