<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs statistics in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94570#M78902</link>
    <description>&lt;P&gt;In SmartConsole go to Manage &amp;amp; Settings &amp;gt; Permissions and Administrators &amp;gt; Administrators&amp;nbsp;&lt;/P&gt;&lt;P&gt;Define a new Administrator and use the &lt;STRONG&gt;Read Only All&lt;/STRONG&gt; Permission Profile&lt;/P&gt;&lt;P&gt;Now when you login using the new Administrator to the Security Management Server you can view the Rules and Logs but without have the option to change anything, just to analyze the logs and rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2020 07:53:48 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2020-08-19T07:53:48Z</dc:date>
    <item>
      <title>Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94117#M78892</link>
      <description>&lt;P&gt;Hi everyone!,&amp;nbsp;I hope you're feeling very well.&lt;/P&gt;&lt;P&gt;Firts thanks for yours replies, I'm new at this, I'm learning.&lt;/P&gt;&lt;P&gt;I have some log files I need to study to refine the firewall rules. Do you know of any software I can install on my computer where I can upload these files and look at the statistics?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 13:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94117#M78892</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-14T13:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94146#M78893</link>
      <description>&lt;P&gt;The log files are a proprietary binary format that can only be read by a Check Point Management/Log Server.&lt;BR /&gt;If you want to view them offline, you’d basically have to set up a separate management server with those logs imported.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 19:46:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94146#M78893</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-14T19:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94191#M78894</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;You can also connected to your Security Management Server with SmartConsole using Read Only credentials or have your administrator set up a dedicated administrator with only the relevant permissions.&lt;/P&gt;
&lt;P&gt;Another option would be to connect to SmartView Log Browser for viewing the logs -&amp;gt; &lt;A href="https://&amp;lt;management" target="_blank"&gt;https://&amp;lt;management_server&amp;gt;/smartview/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Tal&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 18:14:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94191#M78894</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2020-08-15T18:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94493#M78895</link>
      <description>&lt;P&gt;Thanks PhoneBoy, u can recommended me a sotfware?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:00:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94493#M78895</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-18T13:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94494#M78896</link>
      <description>&lt;P&gt;Hello Tal_Peace_Fridman, thank you for responding. How could I load these logs that are no longer on the physical device so that I can view them again on the smartview web and see the statistics there? Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:04:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94494#M78896</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-18T13:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94499#M78897</link>
      <description>&lt;P&gt;SmartView is unable to load logs. The logs have to be on the SMS to be viewed in SmartLog (after indexing), SVTracker (with an open file... option) or elsewhere. To transfer and use the logs on the SMS, see&amp;nbsp;&lt;A id="link_2_688e5800e34abf_8_2c3d9" class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SMB-security-log-files/m-p/39622?search-action-id=16991350586&amp;amp;search-result-uid=39622" target="_blank"&gt;SMB security &lt;SPAN class="lia-search-match-lithium"&gt;log&lt;/SPAN&gt; files&lt;/A&gt;&amp;nbsp;that speaks about SMB logs viewed on SMS. Also read&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39573&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank"&gt;sk39573: How to read a Check Point &lt;STRONG&gt;log&lt;/STRONG&gt; &lt;STRONG&gt;file&lt;/STRONG&gt; in its native format&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92920&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk92920: How to open FireWall &lt;STRONG&gt;log&lt;/STRONG&gt; (fw.&lt;STRONG&gt;log&lt;/STRONG&gt;) from a different Security Management Server in &lt;STRONG&gt;SmartView&lt;/STRONG&gt; Tracker&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94499#M78897</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-18T13:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94502#M78898</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks G_W_Albrecht,&amp;nbsp;I'll take a look at it, if I have problems can I ask you?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:28:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94502#M78898</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-18T13:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94503#M78899</link>
      <description>&lt;P&gt;You can post here...&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:43:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94503#M78899</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-18T13:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94530#M78900</link>
      <description>&lt;P&gt;Hi again&lt;/P&gt;&lt;P&gt;You can use SmartView Web Browser by connecting to the Security Management Server that holds the original files or as I wrote, connecting with Read Only SmartConsole.&lt;/P&gt;&lt;P&gt;This will save you the need to load the files to another machine.&lt;/P&gt;&lt;P&gt;Tal&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 18:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94530#M78900</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2020-08-18T18:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94536#M78901</link>
      <description>&lt;P&gt;Tal_Paz-Fridman thank you very much for helping me, could you explain me how to make these two options or provide me with material to study it?. again thank you and I remain attentive.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 20:21:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94536#M78901</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-18T20:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94570#M78902</link>
      <description>&lt;P&gt;In SmartConsole go to Manage &amp;amp; Settings &amp;gt; Permissions and Administrators &amp;gt; Administrators&amp;nbsp;&lt;/P&gt;&lt;P&gt;Define a new Administrator and use the &lt;STRONG&gt;Read Only All&lt;/STRONG&gt; Permission Profile&lt;/P&gt;&lt;P&gt;Now when you login using the new Administrator to the Security Management Server you can view the Rules and Logs but without have the option to change anything, just to analyze the logs and rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 07:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94570#M78902</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2020-08-19T07:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94574#M78903</link>
      <description>&lt;P&gt;Or, after defining the new&amp;nbsp;Administrator, connect in browser to&amp;nbsp;&lt;A href="https://&amp;lt;SMS_IP&amp;gt;/smartview/" target="_blank"&gt;https://&amp;lt;SMS_IP&amp;gt;/smartview/&lt;/A&gt;&amp;nbsp;and log in there !&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 08:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94574#M78903</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-19T08:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94775#M78904</link>
      <description>&lt;P&gt;Hi again, thanks.&lt;/P&gt;&lt;P&gt;Context:&lt;BR /&gt;I have to make a log study for the previous 3 months, but the index of the firewall administrator is 14 days, I can't access for example in the smartview to consolidated logs of the last 3 months. Do you know if the smartevent also works with this index?&lt;BR /&gt;How can I reconstruct a 3-month index for statistics?&lt;BR /&gt;I have the information but it is very fragmented in daily files and to make 90 statistics and then consolidate them would be a tedious process.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 16:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94775#M78904</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-20T16:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94776#M78905</link>
      <description>&lt;P&gt;Hi again, thanks&lt;/P&gt;&lt;P&gt;Context:&lt;BR /&gt;I have to make a log study for the previous 3 months, but the index of the firewall administrator is 14 days, I can't access for example in the smartview to consolidated logs of the last 3 months. Do you know if the smartevent also works with this index?&lt;BR /&gt;How can I reconstruct a 3-month index for statistics?&lt;BR /&gt;I have the information but it is very fragmented in daily files and to make 90 statistics and then consolidate them would be a tedious process.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 16:23:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/94776#M78905</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-08-20T16:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/95921#M78906</link>
      <description>&lt;P&gt;Assuming your log-files of the needed time (~3 months) still exist &amp;amp; weren't deleted due to log storage capacity (log maintenance), then it's fairly easy.&lt;/P&gt;
&lt;P&gt;follow &lt;SPAN&gt;sk111766 (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=SmartLog" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=SmartLog&lt;/A&gt;)&lt;/SPAN&gt;,&lt;/P&gt;
&lt;P&gt;and add these lines After stopping the Indexer (evstop) &amp;amp; configuring the no. of days you choose (-days_to_index &amp;lt;90&amp;gt; or beyond) to have it completely re-index with your chosen no. of days.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;cp $INDEXERDIR/data/FetchedFiles{,.Orig}&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;rm -f $INDEXERDIR/data/FetchedFiles&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; then start it (&lt;STRONG&gt;evstart&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P&gt;Also make sure to disable/up the daily index files deletion to avoid it from being deleted again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will cause a re-Indexing of these last 3 months of logs (or as many days back as you've configured).&lt;/P&gt;
&lt;P&gt;which has a performance impact during the re-indexing process which should take roughly several days (depending on your log-rate vs. HW strength).&lt;/P&gt;
&lt;P&gt;if you need a better estimation, you can send us your log-rate (or size of log-files) &amp;amp; HW CPU/memory details to better estimate.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 06:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/95921#M78906</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-09-03T06:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/96203#M78907</link>
      <description>&lt;P&gt;Thanks bro I done!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/96203#M78907</guid>
      <dc:creator>sarangoj</dc:creator>
      <dc:date>2020-09-07T12:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Logs statistics</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/96206#M78908</link>
      <description>&lt;P&gt;No problem.&lt;BR /&gt;Glad I could help:)&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 13:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Logs-statistics/m-p/96206#M78908</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-09-07T13:11:41Z</dc:date>
    </item>
  </channel>
</rss>

