<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log File (fw.log) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83000#M80546</link>
    <description>What will happen with the existing active log file (fw.log)...?&lt;BR /&gt;&lt;BR /&gt;Then note that, I am currently on Gaia R80.10 HA, so should I use smart view tracker or import via WinSCP ...?</description>
    <pubDate>Thu, 23 Apr 2020 20:56:54 GMT</pubDate>
    <dc:creator>Dominic</dc:creator>
    <dc:date>2020-04-23T20:56:54Z</dc:date>
    <item>
      <title>Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82940#M80542</link>
      <description>&lt;P&gt;Hi team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to import the log file (fw.log) back to my database because I am forced&amp;nbsp; to generate a report for the previous month.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note; the existing active log file) (fw.log) only has the recent events alone.&lt;/P&gt;&lt;P&gt;Kindly advice.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 14:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82940#M80542</guid>
      <dc:creator>Dominic</dc:creator>
      <dc:date>2020-04-23T14:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82948#M80543</link>
      <description>&lt;P&gt;Not sure I follow.&lt;/P&gt;
&lt;P&gt;Which version are you using?&lt;/P&gt;
&lt;P&gt;Do you want to re-Index the fw.log into the SmartEvent?&amp;nbsp;or do you mean all log-files from the past month?&lt;/P&gt;
&lt;P&gt;Do you need the correlated events as well? which report?&lt;/P&gt;
&lt;P&gt;Please describe the scenario again.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 15:20:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82948#M80543</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-04-23T15:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82985#M80544</link>
      <description>Please note that I'm not trying to achieve anything to do with smart event and re-indexing at the moment.&lt;BR /&gt;Is it possible to import the log file (fw.log) through WinSCP or via smart view tracker back to log server. In either way without any effect on the active log file, what will be the right approach and guideline?</description>
      <pubDate>Thu, 23 Apr 2020 18:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82985#M80544</guid>
      <dc:creator>Dominic</dc:creator>
      <dc:date>2020-04-23T18:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82992#M80545</link>
      <description>&lt;P&gt;You can rename it and copy it back to $FWDIR/log/ in your log server.&lt;/P&gt;
&lt;P&gt;Then you can open it with SmartView Tracker (R77) or using the open file option in SmartConsole (R80+).&lt;/P&gt;
&lt;P&gt;If you have problems you can try to repair it following the procedure from&amp;nbsp;&lt;SPAN&gt;&lt;A title=" SmartView Tracker crashes when attempting to open old (switched) log file" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98929&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk98929&lt;/A&gt;&amp;nbsp;with te command:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;fw repairlog -u&amp;nbsp;&amp;nbsp;&lt;EM&gt;&amp;lt;Name_of_Log_File&amp;gt;&lt;/EM&gt;.log&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Now, if you need to create a report with data from this file, then additional indexing steps will be needed.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 19:19:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/82992#M80545</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2020-04-23T19:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83000#M80546</link>
      <description>What will happen with the existing active log file (fw.log)...?&lt;BR /&gt;&lt;BR /&gt;Then note that, I am currently on Gaia R80.10 HA, so should I use smart view tracker or import via WinSCP ...?</description>
      <pubDate>Thu, 23 Apr 2020 20:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83000#M80546</guid>
      <dc:creator>Dominic</dc:creator>
      <dc:date>2020-04-23T20:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83007#M80547</link>
      <description>&lt;P&gt;First you have to copy the file to $FWDIR/log/ with WinSCP and then you can open it with SmartConsole or SmartView Tracker.&lt;/P&gt;
&lt;P&gt;Rename it first so you won't overwrite the current fw.log.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 22:17:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83007#M80547</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2020-04-23T22:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83009#M80548</link>
      <description>Hi Pedro,&lt;BR /&gt;I did rename it then imported to$FWDIR/log through WinSCP . Funny enough I couldn't view the logs even though it was existing on the console. What I would wish to understand ; should the import happen through the smart view tracker or through WinSCP?</description>
      <pubDate>Thu, 23 Apr 2020 22:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83009#M80548</guid>
      <dc:creator>Dominic</dc:creator>
      <dc:date>2020-04-23T22:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83167#M80549</link>
      <description>You have to use WinSCP to copy the file to the platform before you can use any other tool to read the log file.</description>
      <pubDate>Sun, 26 Apr 2020 01:59:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83167#M80549</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-26T01:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83184#M80550</link>
      <description>&lt;P&gt;Pedro is absolutely correct, but it's safer to close/switch the fw.log (active log-file) 1st, unless that somehow troubles you?&lt;/P&gt;
&lt;P&gt;that is done automatically when it reaches the max size of 2GB or daily (&amp;gt;=R80) or GUI configured.&lt;/P&gt;
&lt;P&gt;so run this:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw logswitch &amp;lt;chosen_name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;# if you don't name, then it names it by default as the current date/time (2020-04-26_091200.log).&lt;/P&gt;
&lt;P&gt;Copy (all &amp;lt;name&amp;gt;.log&lt;STRONG&gt;*&lt;/STRONG&gt;), via scp/winscp or any other way. Put in $FWDIR/log/ &amp;amp; open it via Tracker/Open Log-File.&lt;/P&gt;
&lt;P&gt;If you've already renamed it, then best run the &lt;STRONG&gt;fw repairlog &amp;lt;new-name.log&amp;gt; &lt;/STRONG&gt;&amp;amp; verify it succeeds, &lt;STRONG&gt;then copy all &lt;/STRONG&gt;&amp;lt;name&amp;gt;.log* files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 06:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83184#M80550</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-04-26T06:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Log File (fw.log)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83359#M80551</link>
      <description>&lt;P&gt;You can only open the file with SmartLog or SmartView Tracker after the file is in $FWDIR/log/. When you select the open log file option it will give you a list of log files in $FWDIR/log/. Just select the correct one.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 15:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-File-fw-log/m-p/83359#M80551</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2020-04-27T15:29:32Z</dc:date>
    </item>
  </channel>
</rss>

