- Products
- Learn
- Local User Groups
- Partners
- More
On-Premises SD-WAN Management
Register HereThe industry's first AI Network Firewall
Securing AI traffic, everywhere
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
No Attack Required
Hi,
I am trying to get the Checkpoint logs using API from postman and I could see the below error.
I can see all the logs in the smart console. Please let me know if I need to change any settings.
Thanks
As @PhoneBoy said, your management should be your log server. What do you get with the API call "show-checkpoint-host name <server name> details-level full"? You should see:
"management-blades" : {
...
"logging-and-status" : true,
...
}
...
"logs-settings" : {
"enable-log-indexing" : true,
...
}
If not, then you need to enable the Logging blade on your management object as well as log indexing. The show-logs API requires the indexer to be running. Use SmartConsole to enable both options:
* Edit your management object, select the the "Logging and Status" checkbox in the Products list
* On the left tree, select Logs, and enable Log Indexing
* Click OK, publish changes
You'll have to wait for the indexer to load the logs into the database which can take time, depending on your log size and any historical logs. If you need to load historical logs, then you'll need to use sk111766.
It only shows log server working in index mode. IDK if relevant in your case but if the server is not indexing the logs it might explain the error for no log servers available.
Not sure if any of below would apply in your case, but maybe worth checking...
Hi Thanks, but I see it works in the smart console, but in the API I get this error. So is there any specific settings to configure management server as log server .
Gotcha...just wondering, do you see anything from below command?
https://sc1.checkpoint.com/documents/latest/APIs/?#cli/show-logs~v1.8.1%20
Unless I dont see it, cant really locate section to configure log server, maybe someone else can chime in.
I see server_error with the command
Can you try api restart?
yes, but still the same error
You need "new-query.time-frame" as well.
I get the same error as in the post, when I tried with new-query.time-frame
I assume that I need to configure management server as log server, but I am confused that I can see logs in the Smart Console, not sure if I am right, Please let me know what are the steps to check and change log server configuration.
The management server is the log server unless you've configured an external log and/or SmartEvent server.
What are the hardware specs on your management/log server?
Specify the amount of RAM, CPUs, and disk allocated.
Please find the configuration
RAM - 11GB
CPU- 2 cores
Storage- 200GB
As @PhoneBoy said, your management should be your log server. What do you get with the API call "show-checkpoint-host name <server name> details-level full"? You should see:
"management-blades" : {
...
"logging-and-status" : true,
...
}
...
"logs-settings" : {
"enable-log-indexing" : true,
...
}
If not, then you need to enable the Logging blade on your management object as well as log indexing. The show-logs API requires the indexer to be running. Use SmartConsole to enable both options:
* Edit your management object, select the the "Logging and Status" checkbox in the Products list
* On the left tree, select Logs, and enable Log Indexing
* Click OK, publish changes
You'll have to wait for the indexer to load the logs into the database which can take time, depending on your log size and any historical logs. If you need to load historical logs, then you'll need to use sk111766.
Thanks, after enabling the log indexing, it is working
What is your precise API call?
Also, version/JHF level?
Please find my API call:
and the version is R81 take 392
What are the hardware specs on your management/log server?
Specify RAM, CPUs, and disk allocated.
Not that good with API, but wanted to try this in the lab, except cant open https://mgmtIP:port/web-api link. Let me see whats missing.
Please let me know if this works for you
curl --insecure -XPOST "https://mgmtIP:port/web-api /login" --data-binary "{\"user\": \"xxx\", \"password\": \”xxxx\"}" -H "Content-Type: application/json"
I replaced the values but says curl command not found.
It only shows log server working in index mode. IDK if relevant in your case but if the server is not indexing the logs it might explain the error for no log servers available.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 |
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based ThreatsWed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGTWed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMERWed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEATue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based ThreatsWed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGTWed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMERWed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEAThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY