<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: enable local log storing on cluster in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272434#M45646</link>
    <description>&lt;P&gt;There's two things at play here, regular logging to the log targets, and the log forwarding configuration.&lt;/P&gt;
&lt;P&gt;Regular logging will resume when the management server becomes available again after the upgrade The gateway will regularly retry this connection. From this point, the gateway will send new logs to the management server.&lt;/P&gt;
&lt;P&gt;Log Forwarding occurs at the regular time interval that you configure, the default in R82.10 is at midnight every day. This means that any logs that were stored locally while the gateway was unable to talk to the log server will be transferred over at midnight daily.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2026 01:36:23 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2026-03-04T01:36:23Z</dc:date>
    <item>
      <title>enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272079#M45587</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GW: R81.20&lt;/P&gt;
&lt;P&gt;SMS: R81.20, will be upgraded to R82&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The management server upgrade is planned, and I would like to make sure no log lost during upgrade.&lt;/P&gt;
&lt;P&gt;The cluster is configured to send its log to management server.&lt;/P&gt;
&lt;P&gt;I know a gateway stores its log temporarily in case of no connection to a associated management server, but I would rather configure the gateway to do so just to make sure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My rough draft of plan is:&lt;/P&gt;
&lt;P&gt;1. configure GWs to store its log on themselves&lt;/P&gt;
&lt;P&gt;2. upgrade management server.&lt;/P&gt;
&lt;P&gt;3. check SIC status.&lt;/P&gt;
&lt;P&gt;4. FTP locally stored logs from gateways to management server /var/log/.&lt;/P&gt;
&lt;P&gt;5.chmod and chown log files, giving them same permission and owner.&lt;/P&gt;
&lt;P&gt;6. cpstop/start to make sure management server recognize log files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you reckon this is achievable?&lt;/P&gt;
&lt;P&gt;not sure just putting logs to /var/log/ is enough or not..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 06:31:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272079#M45587</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-02-27T06:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272088#M45594</link>
      <description>&lt;P&gt;The gateway will store logs locally while the management server is not available, this is something you can rely upon. If you want though you can manually enable it for the duration.&lt;/P&gt;
&lt;P&gt;To have locally stored the logs transfer over to the management server, open your gateway properties, expand out Logging, and go to Additional Logging Configuration. At the top of that pane you have Log Forwarding Settings. Enable this to forward logs to your management server at Midnight. This way, at midnight every day, any logs stored on the gateway will be transferred over to the management server and removed off the gateway, saving disk space on the gateway and keeping all your logs in the same place. No need to worry about manually copying files or setting permissions or any of that.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 09:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272088#M45594</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-02-27T09:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272105#M45599</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This should not be needed to do before mgmt upgrade. Just make sure before upgrade you check the disk space on the firewall itself. If there is enough space in /var/log you should be OK.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the mgmt check the dir where the logs are located, see how much GB logs are created per day. For example if there are 10 logs files , 2 GB each for 1 day you need 20GB free on the firewall itself if your mgmt will be 24 hours down.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 13:18:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272105#M45599</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-02-27T13:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272315#M45623</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for sharing information.&lt;/P&gt;
&lt;P&gt;I was not sure local logging is reliable or not, but your comment made me believe I can rely on it.&lt;/P&gt;
&lt;P&gt;I think it is not common sight to stop log forwarding to management server. Our customer wants to do so.&lt;/P&gt;
&lt;P&gt;E/U often makes a request that does not make sense. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing, is locally stored log sent to management server without any manual operation, after the connection is restored?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 04:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272315#M45623</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-03-03T04:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272316#M45624</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciated to your comment.&lt;/P&gt;
&lt;P&gt;The concrete idea of storage space really helps me a lot. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 04:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272316#M45624</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-03-03T04:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272319#M45625</link>
      <description>&lt;P&gt;Locally stored logs are not automatically sent to the management server unless you configured Log Forwarding on the gateway/cluster object how I described in the earlier post, unless this is a newly setup system running R82.10, when it is enabled by default.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 06:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272319#M45625</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-03T06:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272327#M45629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I have learnt it, appreciated!&lt;/P&gt;
&lt;P&gt;Now I am really curious about:&lt;/P&gt;
&lt;P&gt;Does log forwarding automatically resume right after a management server become available?&lt;/P&gt;
&lt;P&gt;How often does the cluster tries resuming log forward to management server while local logging?&lt;/P&gt;
&lt;P&gt;If log forwarding goes well when local logging working, does the gateway switch log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will investigate the points above in my lab. Thanks again!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 08:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272327#M45629</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-03-03T08:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272434#M45646</link>
      <description>&lt;P&gt;There's two things at play here, regular logging to the log targets, and the log forwarding configuration.&lt;/P&gt;
&lt;P&gt;Regular logging will resume when the management server becomes available again after the upgrade The gateway will regularly retry this connection. From this point, the gateway will send new logs to the management server.&lt;/P&gt;
&lt;P&gt;Log Forwarding occurs at the regular time interval that you configure, the default in R82.10 is at midnight every day. This means that any logs that were stored locally while the gateway was unable to talk to the log server will be transferred over at midnight daily.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 01:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272434#M45646</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-04T01:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272435#M45647</link>
      <description>&lt;P&gt;Hey Saitoh,&lt;/P&gt;
&lt;P&gt;What Lesley and Emma said is totally logical and actually fact as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 01:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/272435#M45647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-04T01:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: enable local log storing on cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/273568#M45825</link>
      <description>&lt;P&gt;I have been testing local logging feature, but fw.log will not grow in its size while&amp;nbsp;cpstat fw -f log_connection says the cluster members are saving logs locally due to connectivity problem as follows:&lt;/P&gt;
&lt;P&gt;# watch -d -n 10 "cpstat fw -f log_connection"&lt;/P&gt;
&lt;P&gt;Every 10.0s: cpstat fw -f log_connection Mon Mar 16 21:21:16 2026&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Overall Status: 2&lt;BR /&gt;Overall Status Description: Security Gateway is unable to report logs to any&lt;BR /&gt;log server&lt;BR /&gt;Local Logging Mode Description: Writing logs locally due to connectivity problem&lt;BR /&gt;s&lt;BR /&gt;Local Logging Mode Status: 2&lt;BR /&gt;Local Logging Sending Rate: 0&lt;BR /&gt;Log Handling Rate: 0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Log Servers Connections&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;|IP |Status|Status Description |Sending Rate|&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;|10.xxx.x.xxx| 1|Log-Server Disconnected| 0|&lt;BR /&gt;----------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The target management server has been cpstopped so log server disconnected is an expected output.&lt;/P&gt;
&lt;P&gt;I confirmed the value of Local Logging Sending Rate etc. gets updated according to the connection as expected.&lt;/P&gt;
&lt;P&gt;However, access control/audit log files in the directory $FWDIR/log/, including rotated logs, seemingly get no updates:&lt;/P&gt;
&lt;P&gt;-rw-rw---- 1 admin root 8384 Mar 17 00:00 fw.log&lt;BR /&gt;-rw-rw---- 1 admin root 80 Mar 17 00:00 fw.logaccount_ptr&lt;BR /&gt;-rw-rw---- 1 admin root 80 Mar 17 00:00 fw.loginitial_ptr&lt;BR /&gt;-rw-rw---- 1 admin root 80 Mar 17 00:00 fw.logptr&lt;BR /&gt;-rw-rw---- 1 admin root 1526 Mar 17 00:00 fw.logtrack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some sks tells me that a gateway tries to write logs for every 5 -10 seconds, so I did not expect the modification time of log file to be 00:00.&lt;/P&gt;
&lt;P&gt;Is this normal behaviour?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 02:12:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/enable-local-log-storing-on-cluster/m-p/273568#M45825</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-03-17T02:12:34Z</dc:date>
    </item>
  </channel>
</rss>

