<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Searching Multiple log files by using filter in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14316#M93721</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have new log file after every 2GB size. So each day I collect more than one file of logs.&lt;/P&gt;&lt;P&gt;Recently, I had to search for over few past days. So I was struggling to go into each log file and search.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is there any way to search multiple log files at the same time?&lt;/P&gt;&lt;P&gt;Any query option that allows to select more than one log file.. or any other way (may be third party)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jul 2018 14:46:20 GMT</pubDate>
    <dc:creator>BeaconBits</dc:creator>
    <dc:date>2018-07-30T14:46:20Z</dc:date>
    <item>
      <title>Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14316#M93721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have new log file after every 2GB size. So each day I collect more than one file of logs.&lt;/P&gt;&lt;P&gt;Recently, I had to search for over few past days. So I was struggling to go into each log file and search.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is there any way to search multiple log files at the same time?&lt;/P&gt;&lt;P&gt;Any query option that allows to select more than one log file.. or any other way (may be third party)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 14:46:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14316#M93721</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2018-07-30T14:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14317#M93722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which version is your management running?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium;"&gt;&amp;nbsp;On R80.x logs are automatically indexed (as long as indexing is not turned off) and a search will search over all indexed log-files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;On R77.x (or older) logs in SmartView Tracker are not indexed, but in SmartLog they are.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 15:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14317#M93722</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-07-30T15:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14318#M93723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is on R80.10.&lt;/P&gt;&lt;P&gt;In this case then how can I check if log files are indexed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 15:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14318#M93723</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2018-07-30T15:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14319#M93724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Norbert &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found this option on Log Server and it is enabled.&lt;/P&gt;&lt;P&gt;S it means, that I can go back only up to 14 days at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67730_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;Could you please add more relevant info that I'm missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 15:50:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14319#M93724</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2018-07-30T15:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14320#M93725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe it all depends how your "log infrastructure" looks like,&lt;/P&gt;&lt;P&gt;if you're using CLM (Log Server) there are options for making that simpified&lt;/P&gt;&lt;P&gt;if your logs ends on SMS server - I don't think you can search few ELG files at the same time if I'm not mistaken (unless the script is already known to our belowed CCSM's here &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;if your log switching is done per "size" on your Management Server (SMS) then obviously it must be a pain (and it is for each and everyone I guess) including myself to go trouch all the logs in order to find interesting record however, as Norbert mentioned in R80.10 for instance it should "per indexing" at least show you a snip of the record you're lookinig for. IMHO CLM is the best option, unless your logging facility does not need 12 months of log retention ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 15:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14320#M93725</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-07-30T15:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14321#M93726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;open the object in your dash and see if the indexing (in logging section) is enabled - if not - enabled it manually.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 08:12:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14321#M93726</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-07-31T08:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14322#M93727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is called btw "Enable Log Indexing" with a little blue "i" icon &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 08:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14322#M93727</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-07-31T08:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Searching Multiple log files by using filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14323#M93728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67757_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;So far what I understand is that I can search up to last 14 days because logs are being indexed to 14.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But searching multiple random files before these 14 days is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Checkpoint: Not sure, but I think there should be feature where to select multiple log files and search from them at once rather selecting one by one that are not indexed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 08:58:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-Multiple-log-files-by-using-filter/m-p/14323#M93728</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2018-08-01T08:58:56Z</dc:date>
    </item>
  </channel>
</rss>

