<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reports data loss in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164393#M27429</link>
    <description>&lt;P&gt;When upgrading to an R81.x release from an R80.x release, you will need to manually reindex the logs after upgrading.&lt;BR /&gt;This is because we’ve changed the index format in R81.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=Logging" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=Logging&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2022 23:52:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-12-06T23:52:36Z</dc:date>
    <item>
      <title>Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164387#M27427</link>
      <description>&lt;P&gt;Hello Mates!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a distributed environment (SMS + Gateway Cluster + Smart Event and Logs) and did an upgrade on SMS and Smart Event from 80.40 to 81.10. The SMS upgrade was by migrate process(create a new VM) and the Smart Event was by CPUSE.&lt;/P&gt;&lt;P&gt;After that, I can't see the reports about Application and URL Filtering or any other blade, look at this example bellow:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image_2022-12-06_201146225.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18663i54927B01D13BADFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image_2022-12-06_201146225.png" alt="image_2022-12-06_201146225.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I filter by "All Time" it just shows me this month which is the date I did the upgrade until now.&lt;/P&gt;&lt;P&gt;As I said, the Smart Event doesn't change, the upgrade was by CPUSE, but to the SMS was created a new VM and imported the migrate file.&lt;/P&gt;&lt;P&gt;Is there anything missing to bring from the old SMS to the new SMS so that I can see the old report information from other months?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 23:19:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164387#M27427</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2022-12-06T23:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164389#M27428</link>
      <description>&lt;P&gt;Did you move and reindex the old log data?&lt;/P&gt;
&lt;P&gt;R81&lt;/P&gt;
&lt;P&gt;GNG-1259,&lt;/P&gt;
&lt;P&gt;PMTR-52941 R81 includes new logs indexing mechanism, so when upgrading Management server/Log Server/Multi-Domain Server/Multi-Domain Log Server/SmartEvent from R80.x, old log indexes are not upgraded.&lt;/P&gt;
&lt;P&gt;The indexing mechanism will re-index the last 24 hours automatically. To increase the period of offline indexing (how far in the past to re-index the logs), see sk111766.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 23:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164389#M27428</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-06T23:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164393#M27429</link>
      <description>&lt;P&gt;When upgrading to an R81.x release from an R80.x release, you will need to manually reindex the logs after upgrading.&lt;BR /&gt;This is because we’ve changed the index format in R81.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=Logging" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111766&amp;amp;partition=Advanced&amp;amp;product=Logging&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 23:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164393#M27429</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-06T23:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164394#M27430</link>
      <description>&lt;P&gt;You got 100% correct answers from Chris and Dameon, as thats exactly what you need to do. I been through this 3 times before and that was sk I had to follow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 01:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164394#M27430</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-07T01:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164425#M27434</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;! First of all, thank you very much!&lt;/P&gt;&lt;P&gt;I did the process of index old logs and configured for 60 days both on "&lt;SPAN&gt;./log_indexer -days_to_index 60" and in the storage config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After that, I can see logs just 14 days since yesterday to back.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="print2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18666i0D8B20C5368C8EA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="print2.png" alt="print2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I saw the secondary process of the sk164553, but I didn't understand very well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this second process from&amp;nbsp;sk164553 is mandatory or it already would works with just the process of the index (./log_indexer -days_to_index 60) ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 12:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164425#M27434</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2022-12-07T12:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164434#M27435</link>
      <description>&lt;P&gt;The procedure in&amp;nbsp;&lt;SPAN&gt;sk164553 is if you need to index a specific log file.&lt;BR /&gt;If you’re indexing the last 60 days of logs per your CLI command this shouldn’t be necessary.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note that it can take some time to index the log files since it is done at a lower priority.&lt;BR /&gt;You will see the CPU utilization on the management server higher than normal as a result, but the indexing process backs off when the CPU is needed for other tasks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 13:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164434#M27435</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-07T13:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164435#M27436</link>
      <description>&lt;P&gt;Keep in mind, it may take 24 hours for all to show up, I seen that before myself.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 13:57:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164435#M27436</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-07T13:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164573#M27439</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thank you for the explanation!&lt;/P&gt;&lt;P&gt;I can see a high-load CPU on Smart Event appliance indeed. And slowly I saw the old log being shown on the smart console.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 18:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164573#M27439</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2022-12-08T18:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Reports data loss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164574#M27440</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;thank you for the advice!&lt;/P&gt;&lt;P&gt;It has taken more than 3 days and just now I can see de CPU in normal use.&lt;/P&gt;&lt;P&gt;Is there any way to monitor when the index process is running or is finished?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 18:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Reports-data-loss/m-p/164574#M27440</guid>
      <dc:creator>Bernardes</dc:creator>
      <dc:date>2022-12-08T18:42:46Z</dc:date>
    </item>
  </channel>
</rss>

