- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Gentlemen... people... I hope you are all well?!? I would like to share a situation that has been happening to someone where the active member of the r81.10 take 172 cluster,appliance series 7000 gradually fills the /var/log partition of the fw gw until it is almost full and when it is full, it starts deleting and freeing up the partition. I have only been following all hours this behavior and it soon returns to normal and goes months without happening. Have you ever experienced this? Any experience in this regard?
tks rodrigo
It sounds like it's logging locally, is it having trouble communicating with its configured log servers?
What does this command say?
cpstat mg -f log_server // on SmartCenter
cpstat fw -f log_connection // on gateway
BR
Akos
Sounds like what @emmap mentioned was indeed the case.
Andy
Hey Rodrigo,
Maybe there is cron job you might not be aware of possibly? I had seen that dir fill up, but then most people just delete whatever is not needed.
Example, say you wish to look for files bigger than 500 MBs, you would run -> find /var/log -size +500M
Best,
Andy
One thing I thought of as well is check to make sure maybe there are no files from before that are "lingering" in that dir that could be deleted.
Andy
It sounds like it's logging locally, is it having trouble communicating with its configured log servers?
What does this command say?
cpstat mg -f log_server // on SmartCenter
cpstat fw -f log_connection // on gateway
BR
Akos
Hello.. How are you?!? The output of the command in fw (cpstat fw -f log_connection)
is informing that one of the logservers is unavailable and is saving locally (the VM is actually turned off and being migrated to another environment) and I had not removed the logserver from the log sending configurations of the clusters. I removed it now and just left the logserver active until the migration is finished and I will follow up on the case.
For now, thank you very much.
Sounds like what @emmap mentioned was indeed the case.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY