<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to control/limit the output file size from fw monitor in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109307#M20757</link>
    <description>&lt;P&gt;fw monitor was never designed to be run long-term like that.&lt;BR /&gt;Not sure there’s a great way to achieve what you’re looking for.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 17:48:52 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-01-29T17:48:52Z</dc:date>
    <item>
      <title>How to control/limit the output file size from fw monitor</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109300#M20756</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would like to record a trace with fw monitor over a few weeks period. How can i control the file size in order to not accidentaly fill the whole disk?&lt;/P&gt;&lt;P&gt;Even if i let the trace run for a week or two it would be sufficient for me to just have tha last 24 Hours from the moment i stop the trace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards and thanks,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 15:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109300#M20756</guid>
      <dc:creator>ironshirt</dc:creator>
      <dc:date>2021-01-29T15:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to control/limit the output file size from fw monitor</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109307#M20757</link>
      <description>&lt;P&gt;fw monitor was never designed to be run long-term like that.&lt;BR /&gt;Not sure there’s a great way to achieve what you’re looking for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 17:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109307#M20757</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-29T17:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to control/limit the output file size from fw monitor</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109337#M20762</link>
      <description>&lt;P&gt;&lt;STRONG&gt;fw monitor&lt;/STRONG&gt; (both &lt;STRONG&gt;-e&lt;/STRONG&gt; and &lt;STRONG&gt;-F&lt;/STRONG&gt;) does not have any built-in abilities to limit the file size of the capture, nor can it automatically rotate the capture files as the capture is running to keep them from getting too large.&amp;nbsp; It can set a "dead man's switch" limit of total packets to capture before terminating itself with the &lt;STRONG&gt;-ci&lt;/STRONG&gt; and &lt;STRONG&gt;-co&lt;/STRONG&gt; options.&amp;nbsp; Also a &lt;STRONG&gt;fw monitor -e&lt;/STRONG&gt; capture will not survive a policy installation on the gateway (but &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; will).&amp;nbsp; So &lt;STRONG&gt;fw monitor&lt;/STRONG&gt; is probably not the tool you should use here.&lt;/P&gt;
&lt;P&gt;On the other hand &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; does have the ability to automatically rotate &amp;amp; limit log files for running captures (&lt;STRONG&gt;-C&lt;/STRONG&gt; and &lt;STRONG&gt;-G&lt;/STRONG&gt; flags) and &lt;STRONG&gt;cppcap&lt;/STRONG&gt; also picked up this ability in R81 via the &lt;STRONG&gt;-w&lt;/STRONG&gt; and &lt;STRONG&gt;-W&lt;/STRONG&gt; flags.&amp;nbsp; These tools will also survive a policy installation while executing a long-running capture, but I'd advise capturing only on a single interface and use an extremely specific filter if possible.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 14:34:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-control-limit-the-output-file-size-from-fw-monitor/m-p/109337#M20762</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-01-30T14:34:21Z</dc:date>
    </item>
  </channel>
</rss>

