<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Messages with /var/log in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199736#M33363</link>
    <description>&lt;P&gt;1| Check if you have crash of dump files which usually take a lot of space:&lt;/P&gt;
&lt;P&gt;/var/log/crash/&lt;/P&gt;
&lt;P&gt;/var/log/dump/usermode/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2| As for elg files you can usually delete the ones with a number a the end, for example:&lt;/P&gt;
&lt;P&gt;cpm.elg.1&lt;BR /&gt;cpm.elg.10&lt;BR /&gt;cpm.elg.11&lt;BR /&gt;cpm.elg.12&lt;BR /&gt;cpm.elg.13&lt;BR /&gt;cpm.elg.14&lt;BR /&gt;cpm.elg.15&lt;BR /&gt;cpm.elg.2&lt;BR /&gt;cpm.elg.3&lt;BR /&gt;cpm.elg.4&lt;BR /&gt;cpm.elg.5&lt;BR /&gt;cpm.elg.6&lt;BR /&gt;cpm.elg.7&lt;BR /&gt;cpm.elg.8&lt;BR /&gt;cpm.elg.9&lt;/P&gt;
&lt;P&gt;(but it means that debug information will be lost if needed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3| Please also look at log retention and cleanup settings on the object (in SmartConsole)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 12:45:39 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2023-12-05T12:45:39Z</dc:date>
    <item>
      <title>Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199731#M33362</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Can the messages file be removed/deleted from /var/log without any consequences.&lt;/P&gt;&lt;P&gt;Trying to upgrade Firewall from R81.10 to R81.20 and the /var/log partition is 90% full.&lt;/P&gt;&lt;P&gt;I could also see a lot of .elg files within $FWDIR/log. Can this also be removed/deleted without any consequences?&lt;/P&gt;&lt;P&gt;Thanks Always&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Olu&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 12:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199731#M33362</guid>
      <dc:creator>Olusegun_Adekun</dc:creator>
      <dc:date>2023-12-05T12:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199736#M33363</link>
      <description>&lt;P&gt;1| Check if you have crash of dump files which usually take a lot of space:&lt;/P&gt;
&lt;P&gt;/var/log/crash/&lt;/P&gt;
&lt;P&gt;/var/log/dump/usermode/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2| As for elg files you can usually delete the ones with a number a the end, for example:&lt;/P&gt;
&lt;P&gt;cpm.elg.1&lt;BR /&gt;cpm.elg.10&lt;BR /&gt;cpm.elg.11&lt;BR /&gt;cpm.elg.12&lt;BR /&gt;cpm.elg.13&lt;BR /&gt;cpm.elg.14&lt;BR /&gt;cpm.elg.15&lt;BR /&gt;cpm.elg.2&lt;BR /&gt;cpm.elg.3&lt;BR /&gt;cpm.elg.4&lt;BR /&gt;cpm.elg.5&lt;BR /&gt;cpm.elg.6&lt;BR /&gt;cpm.elg.7&lt;BR /&gt;cpm.elg.8&lt;BR /&gt;cpm.elg.9&lt;/P&gt;
&lt;P&gt;(but it means that debug information will be lost if needed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3| Please also look at log retention and cleanup settings on the object (in SmartConsole)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 12:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199736#M33363</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-12-05T12:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199741#M33365</link>
      <description>&lt;P&gt;Hi Tal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for you swift response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The var/log/crash is actually fast empty only 4.0k&lt;/P&gt;&lt;P&gt;Can I delete the messages with numbers as well.&lt;/P&gt;&lt;P&gt;messages.1&lt;/P&gt;&lt;P&gt;messages.2&amp;nbsp;&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Olu&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 12:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199741#M33365</guid>
      <dc:creator>Olusegun_Adekun</dc:creator>
      <dc:date>2023-12-05T12:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199761#M33366</link>
      <description>&lt;P&gt;Yes but I do not think they will save you that much space.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps you could increase disk space or change partitions?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk95566" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk95566&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199761#M33366</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-12-05T14:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199776#M33369</link>
      <description>&lt;P&gt;Thanks. Appreciate.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199776#M33369</guid>
      <dc:creator>Olusegun_Adekun</dc:creator>
      <dc:date>2023-12-05T16:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199781#M33370</link>
      <description>&lt;P&gt;I agree with Tal, it is extremely unlikely deleting /var/log/messages files and elg files will free much space. Even with extreme levels of logging, those files collectively should never take up even a whole gigabyte.&lt;/P&gt;
&lt;P&gt;Instead, look in $FWDIR/log at firewall logs. This is the common set of files per day of log data:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2023-11-25_000000.adtlog
2023-11-25_000000.adtlogaccount_ptr
2023-11-25_000000.adtloginitial_ptr
2023-11-25_000000.adtlogptr
2023-11-25_000000.log
2023-11-25_000000.logaccount_ptr
2023-11-25_000000.loginitial_ptr
2023-11-25_000000.logptr&lt;/LI-CODE&gt;
&lt;P&gt;They may be rotated multiple times per day, depending on your traffic log volume. For example, they automatically rotate when the traffic log hits 2 GB. I have one environment which gets over 40 GB of log data per day, so the files rotate a lot.&lt;/P&gt;
&lt;P&gt;After traffic logs, the next big items are core dumps as Tal mentioned, then CPUSE packages (check 'installer delete' in clish to see what packages you can delete. Backups saved to /var/log/CPbackup and snapshots exported to /var/log/CPsnapshot also take up a lot of space. Note that snapshots you don't export don't take up any space in the filesystem (they are stored in unallocated space in the drive).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:42:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199781#M33370</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-12-05T16:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Messages with /var/log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199792#M33373</link>
      <description>&lt;P&gt;Please send output of below...it will show any files in /var/log bigger than 500M&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;from expert mode -&amp;gt; find /var/log -size 500M&lt;/P&gt;
&lt;P&gt;Also, make sure fw is NOT logging local by doing this:&lt;/P&gt;
&lt;P&gt;watch -d ls -lh $FWDIR/log/fw.log&lt;/P&gt;
&lt;P&gt;Output should always show 8.2K, which is default fw size for this file, as logs would always be sent to the mgmt server (unless its standalone box, which literally no one I know uses)&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;From my lab:&lt;/P&gt;
&lt;P&gt;[Expert@CP-gw:0]# cd $FWDIR/log&lt;BR /&gt;[Expert@CP-gw:0]# ls -lh fw.&lt;BR /&gt;fw.adtlog fw.adtlogaccount_ptr fw.adtlogptr fw.logaccount_ptr fw.logptr&lt;BR /&gt;fw.adtlogLuuidDB fw.adtloginitial_ptr fw.log fw.loginitial_ptr fw.logtrack&lt;BR /&gt;[Expert@CP-gw:0]# ls -lh fw.log&lt;BR /&gt;-rw-rw---- 1 admin root 8.2K Nov 28 00:00 fw.log&lt;BR /&gt;[Expert@CP-gw:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 19:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Messages-with-var-log/m-p/199792#M33373</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-05T19:30:19Z</dc:date>
    </item>
  </channel>
</rss>

