<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191549#M73954</link>
    <description>&lt;P&gt;From R80.xx to R81.xx there's a different version of SOLR (newer version has newer SOLR that works better) so everything will need to be re-indexed so don't bother exporting/importing your indexes. So instead of using -x (export logs and indexes) you can use -l (export logs only) and that will be faster.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 09:23:05 GMT</pubDate>
    <dc:creator>Amir_Senn</dc:creator>
    <dc:date>2023-09-05T09:23:05Z</dc:date>
    <item>
      <title>Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/133981#M73944</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking to migrate our current R80.30 MDM +MLM to R81.10 on new servers.&amp;nbsp; I have tested with migrate_server export -v R81.10 -x &amp;lt;filename&amp;gt; on the MDM as a starting point but in R81.10 SmartConsole we see what appears to only go back to midnight of the previous day from when the migrate_server was run.&amp;nbsp; How can we extend that back to include all traffic/audit logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2021 02:56:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/133981#M73944</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-11-14T02:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/133984#M73945</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Important note&lt;/U&gt;: You won’t be able to preserve log-Indexes (the actual SME log-DB), if you’re upgrading to R81.x from R80.x, as the Solr I/S had been upgraded.&lt;/P&gt;
&lt;P&gt;so this procedure should only be done on R80.x to R80.x or R81.x to R81.x (like R80.20 to R80.40 or R81 to R81.10).&lt;/P&gt;
&lt;P&gt;If upgrading to R81, then you can enlarge the indexing backwards time limit to &lt;U&gt;index&lt;/U&gt; older logs/events - more than the default 1 day back (assuming the actual log-files from its Log-Servers still exist).&lt;BR /&gt;See &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=SmartLog" target="_blank" rel="noopener"&gt;sk111766.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 12:23:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/133984#M73945</guid>
      <dc:creator>Ido_Shoshana</dc:creator>
      <dc:date>2021-11-16T12:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134110#M73946</link>
      <description>&lt;P&gt;If it's not possible for the log indexes, how about the raw log files after doing a logswitch and copy those over or is that not an option?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 19:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134110#M73946</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-11-15T19:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134129#M73947</link>
      <description>&lt;P&gt;yes, this is an option since the log files are kept.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:14:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134129#M73947</guid>
      <dc:creator>Ido_Shoshana</dc:creator>
      <dc:date>2021-11-16T08:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134130#M73948</link>
      <description>&lt;P&gt;That's great!&amp;nbsp; So all we'd need to do is copy over the old raw log files to the new server?&amp;nbsp; Are they in the same format and don't need any sort of script to be run to be able to be read by R81.10?&amp;nbsp; If we do that could we also then also follow the SK you mentioned to index the additional days as well?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134130#M73948</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-11-16T08:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134149#M73949</link>
      <description>&lt;P&gt;No need to copy. The log files should have already been imported as part of the migrate server as you have shown above (-x / -l).&lt;/P&gt;
&lt;P&gt;Yes, same format - all good. Then you can follow the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=SmartLog" target="_blank" rel="noopener noreferrer"&gt;sk111766&lt;/A&gt; to re-index back as many log files days of data as you wish.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 14:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/134149#M73949</guid>
      <dc:creator>Ido_Shoshana</dc:creator>
      <dc:date>2021-11-16T14:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/182288#M73950</link>
      <description>&lt;P&gt;For MLM migration on new hardware running same version (R81.10), if we are not worried about log files migration,&amp;nbsp;&lt;SPAN&gt;migrate_server export -v R81.10 -x &amp;lt;filename&amp;gt; should be enough. Is that correct?&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 16:46:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/182288#M73950</guid>
      <dc:creator>SunilShivnani1</dc:creator>
      <dc:date>2023-05-26T16:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191543#M73951</link>
      <description>&lt;P&gt;And what about Mgmt upgrade from R80.40 to R81.20? We tried exporting 30 days of logs, but it took a lot of time. We decided to archive the logs, delete them and do migrate export with 5 days of logs. Can we just copy the archived logs back to R81.20 Mgmt and index them?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 08:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191543#M73951</guid>
      <dc:creator>Maja_B</dc:creator>
      <dc:date>2023-09-05T08:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191546#M73952</link>
      <description>&lt;P&gt;Yes you can manually copy log files over (make sure you have all the pointer files as well) and (optionally) re-index them.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 08:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191546#M73952</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2023-09-05T08:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191547#M73953</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 08:45:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191547#M73953</guid>
      <dc:creator>Maja_B</dc:creator>
      <dc:date>2023-09-05T08:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191549#M73954</link>
      <description>&lt;P&gt;From R80.xx to R81.xx there's a different version of SOLR (newer version has newer SOLR that works better) so everything will need to be re-indexed so don't bother exporting/importing your indexes. So instead of using -x (export logs and indexes) you can use -l (export logs only) and that will be faster.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 09:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191549#M73954</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2023-09-05T09:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191566#M73955</link>
      <description>&lt;P&gt;Hi Maja_B,&lt;BR /&gt;&lt;BR /&gt;As my colleagues said, the SOLR version was upgraded in Version R81 and above, I would recommend for an upgrade from R80.xx versions to use (migrate_server export -v R81.xx -l &amp;lt;file name&amp;gt;) command to export only the log files not including the indexes.&lt;BR /&gt;&lt;BR /&gt;this will transfer all logs under $FWDIR/log to the new version, than you may increase the days to index backwards as much days as you desire, you can track the index process with the following command (watch -d 'cat $INDEXERDIR/data/FetchedFiles').&lt;BR /&gt;&lt;BR /&gt;to increase the days to index, just follow this simple steps:&lt;BR /&gt;1) cp $INDEXERDIR/log_indexer_custom_settings.conf&amp;nbsp;$INDEXERDIR/log_indexer_custom_settings.conf.ORIGINAL&lt;/P&gt;
&lt;P&gt;2) vi&amp;nbsp;$INDEXERDIR/log_indexer_custom_settings.conf&lt;/P&gt;
&lt;P&gt;3) add under ":max_disk_space_usage (0)" the following ":days_to_index (&amp;lt;number of days&amp;gt;)" then save changes&lt;/P&gt;
&lt;P&gt;4) run 'stopIndexer' &amp;amp; 'startIndexer'&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Kind regards, Daniel Fidlin&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 11:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191566#M73955</guid>
      <dc:creator>Daniel_Fidlin</dc:creator>
      <dc:date>2023-09-05T11:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191620#M73956</link>
      <description>&lt;P&gt;Thanks. We already did it with -l flag.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191620#M73956</guid>
      <dc:creator>Maja_B</dc:creator>
      <dc:date>2023-09-05T14:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating MDM/MLM from R80.30 to R81.10 with all logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191621#M73957</link>
      <description>&lt;P&gt;Thanks, Daniel!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:57:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrating-MDM-MLM-from-R80-30-to-R81-10-with-all-logs/m-p/191621#M73957</guid>
      <dc:creator>Maja_B</dc:creator>
      <dc:date>2023-09-05T14:57:45Z</dc:date>
    </item>
  </channel>
</rss>

