<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW logs missing -- all other lost are available in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130553#M74381</link>
    <description>&lt;P&gt;Definitely sounds like a log indexing issue; my experience is that TAC will normally need to figure out what is happening.&amp;nbsp; If you'd like to avoid a full reboot in the future for resolution, run these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;stopIndexer&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;startIndexer&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the problem still persists try these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;evstop&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;evstart&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 12:02:37 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-09-29T12:02:37Z</dc:date>
    <item>
      <title>FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130492#M74373</link>
      <description>&lt;P&gt;I have an odd one.&amp;nbsp; Over the weekend I had a customer running 80.30 JHF236 stop logging all FW events.&amp;nbsp; Logging is working as expected.&amp;nbsp; GW log files are not incrementing, the date and time is good, SmartLog shows recent App/URLF/TE logs.&amp;nbsp; I have rebooted each GW in the cluster as well as the log server.&amp;nbsp; Still no logs.&amp;nbsp; When I say I see not FW logs that is not exactly true.&amp;nbsp; Any FW log with and "alert" type shows up.&amp;nbsp; But regular accepts/drops for sessions or connections are not visible.&amp;nbsp; If I go back to Tracker (CPlgv.exe) I can see the FW logs.&amp;nbsp; Any thoughts or ideas?&lt;/P&gt;&lt;P&gt;Tracker:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FW-Tracker.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13804iA6047B602CE28D2D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FW-Tracker.png" alt="FW-Tracker.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; SmartLog:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SmartLog.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13805i0DE54F06D0AE2389/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SmartLog.png" alt="SmartLog.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 19:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130492#M74373</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2021-09-28T19:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130495#M74374</link>
      <description>&lt;P&gt;Hm, could be log indexing issue, sounds like, but not 100% sure. Do you have that enabled?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 21:13:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130495#M74374</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-28T21:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130496#M74375</link>
      <description>&lt;P&gt;Yes, its been a working installation for years.&amp;nbsp; All was working fine until Saturday.&amp;nbsp; Boxes not pegged or exhausted and they have been rebooted within the past 45 days.&amp;nbsp; I guess what I didn't explain before is my environment is distributed.&amp;nbsp; Separate SMS/Log/SE.&amp;nbsp; The only thing I did not reboot was the SMS.&amp;nbsp; After rebooting it, it was resolved.&amp;nbsp; Still, no signs of problems before reboot.&amp;nbsp; Odd for sure.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 21:17:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130496#M74375</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2021-09-28T21:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130499#M74376</link>
      <description>&lt;P&gt;I agree with you brother, it is odd, for sure. I will tell you, normally what I follow to fix any logging issue is below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk38848" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk38848&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;Change $FWDIR/conf/masters file on gateway(s) to reflect management object IP rather than name and then apply below sk:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102712&amp;amp;srcFavorites=favorites" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102712&amp;amp;srcFavorites=favorites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There is "old school" way of fixing logging too, but I shall not mention it here, as probably no one uses it any more anyway : )&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 21:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130499#M74376</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-28T21:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130500#M74377</link>
      <description>&lt;P&gt;Yup.&amp;nbsp; I do installs/upgrades/troubleshooting for a living.&amp;nbsp; I'm very familiar with both of those SKs.&amp;nbsp; I am used to seeing logs work or not work, not some logs work and some not (from the same log source).&amp;nbsp; I just never figured it would be the SMS since it doesn't do the indexing, but what do I know?&amp;nbsp; You learn something new every day.&amp;nbsp; Thanks for the input.&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 21:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130500#M74377</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2021-09-28T21:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130519#M74378</link>
      <description>&lt;P&gt;When you open the logfile itself, is the info there?&lt;/P&gt;
&lt;DIV id="tinyMceEditor_89f5afbd320a7bMaarten_Sjouw_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_89f5afbd320a7bMaarten_Sjouw_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Open logfile.PNG" style="width: 431px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13806iB25E3F18EC94C49E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Open logfile.PNG" alt="Open logfile.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 07:06:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130519#M74378</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2021-09-29T07:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130530#M74379</link>
      <description>&lt;P&gt;I just have to take a guess on the old school methods:&lt;/P&gt;
&lt;P&gt;- Replace log server with dummy object with same IP as "proper" log server.&amp;nbsp; Push policy. Swap out with proper log server and push policy.&lt;/P&gt;
&lt;P&gt;&amp;lt;or&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Nuke from orbit (aka delete FetchedFiles)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 09:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130530#M74379</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-09-29T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130534#M74380</link>
      <description>&lt;P&gt;The SMS in fact does do the indexing - you enable it on SMS Tab Logs...&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 09:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130534#M74380</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-29T09:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130553#M74381</link>
      <description>&lt;P&gt;Definitely sounds like a log indexing issue; my experience is that TAC will normally need to figure out what is happening.&amp;nbsp; If you'd like to avoid a full reboot in the future for resolution, run these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;stopIndexer&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;startIndexer&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the problem still persists try these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;evstop&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;evstart&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 12:02:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130553#M74381</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-09-29T12:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130556#M74382</link>
      <description>&lt;P&gt;Yes, there were logs in there.&amp;nbsp; I actually opened it through tracker though, I forgot about that piece in SmartLog.&amp;nbsp; I assume if its visible in tracker it would be visible there.&amp;nbsp; Or is that an indexed 2G file?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 12:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130556#M74382</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2021-09-29T12:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130562#M74383</link>
      <description>&lt;P&gt;Yup, pretty much on both &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 13:08:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130562#M74383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-29T13:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: FW logs missing -- all other lost are available</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130636#M74384</link>
      <description>&lt;P&gt;It is the same, just not the indexed piece.&lt;BR /&gt;I have had many issues with logging in R80.30 and R80.40 and had to do a evstop and mdsstart to get it to resolve, but in your case it sounds like there is an issue with the indexer itself or there is a an issue in Solr, however rebooting the SMS and log server should resolve that.&amp;nbsp;&lt;BR /&gt;Do keep in mind that your not directly connecting to the log server but to the SMS which is forwarding your request to the log server. so you should also do the evstop/cpstart on the SMS.&lt;/P&gt;
&lt;P&gt;To restart Solr only:&lt;/P&gt;
&lt;P&gt;cd /opt/CPrt-R81/scripts/&lt;BR /&gt;./stopSolr.sh;./startSolr.sh&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 07:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-logs-missing-all-other-lost-are-available/m-p/130636#M74384</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2021-09-30T07:41:39Z</dc:date>
    </item>
  </channel>
</rss>

