- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
We recently replaced our open server hardware that was running the dedicated log server. I moved only the .log files (not other log files) from /var/log/opt/CPsuite-R81.20/fw1/log/2024-11-*.log to /var/log/opt/CPsuite-R81.20/fw1/log/ on another server ranging from 2024-11-1 to 2024-11-19.
I’m wondering how indexing works after this transfer. Does it happen automatically, or do I need to manually re-index the logs? I only need the last 14 days of indexed logs.
It seems like the article I found is relevant, but I wanted to confirm: is moving just the .log files sufficient, or should I have moved the other log files as well?
There are "pointer" files that are necessary for working with the logs (thus why the instructions state to copy $FWDIR/log/*.log* instead of $FWDIR/log/*.log.
I was mistaken that they are rebuilt automatically, you'd have to use fw repairlog (from the CLI) to do that.
As for whether the logs will get imported/indexed automatically, I would assume this would not be the case if you simply copied the files over.
Starting the reindexing process (as described in the SK) ensures this will be done.
The time will depend on the amount of logs, overall management/log server load, etc.
You will notice some increased CPU during this time, which will "back off" when other management processes need to use the CPU.
This is normal, expected behavior.
steps that I followed to resolve this issue:
Running sk111766 and then performing the below:
(I went through these steps but I am not sure if it fixed the issue. I was not seeing any indexed logs even after going through them)
The following steps actually started showing indexed logs in smart console.
Go to expert mode: fw repairlog -u 2024-11-15_032113_2226.log (you have to repair all the logs file that you want to repair)
After running fw repair log, I am seeing indexed logs. Thanks!
While I believe the log files alone are sufficient, the other files have to be rebuilt if they are not transferred.
It's better to move them all.
And yes, you will have to manually reindex the logs after moving files into the directory.
what does "rebuilt if they are not transferred mean"?
I just copied all the .log files and followed instruction from this sk artice:
https://support.checkpoint.com/results/sk/sk111766
I am not sure if it indexed logs or not. How can I verify that? How long does it generally take to re-index logs?
Don't forget, indexing the logs takes a while.
And don't forget evstop, and evstart. Ususallly thats why we don't apply this after upgrades. Is not worth the time.
Akos
There are "pointer" files that are necessary for working with the logs (thus why the instructions state to copy $FWDIR/log/*.log* instead of $FWDIR/log/*.log.
I was mistaken that they are rebuilt automatically, you'd have to use fw repairlog (from the CLI) to do that.
As for whether the logs will get imported/indexed automatically, I would assume this would not be the case if you simply copied the files over.
Starting the reindexing process (as described in the SK) ensures this will be done.
The time will depend on the amount of logs, overall management/log server load, etc.
You will notice some increased CPU during this time, which will "back off" when other management processes need to use the CPU.
This is normal, expected behavior.
steps that I followed to resolve this issue:
Running sk111766 and then performing the below:
(I went through these steps but I am not sure if it fixed the issue. I was not seeing any indexed logs even after going through them)
The following steps actually started showing indexed logs in smart console.
Go to expert mode: fw repairlog -u 2024-11-15_032113_2226.log (you have to repair all the logs file that you want to repair)
After running fw repair log, I am seeing indexed logs. Thanks!
Hello,
Is it possible, to import (copy) index files (audit, other, firewallandvp, smartevent) from backup and use them instead of waiting (for example a week) for reindexing? What are the requirements for this procedure (e.g. FetchedFiles modifications or anything like that)?
Regards
Mirek
And what that output from doctor-log means (after manual copying archive indexes):
"other_2025-07-13T00-00-00 should be transient, should have changed to transient after 30 days"
Maintenance Configuration:
Maintenance type : daily
Keep logs for : 730
Delete indexes older than: 365 days
In $INDEXERDIR/log_indexer_custom_settings.conf
:days_to_index (120)
In SMS Logs->Storage Daily Logs Retention Configuration:
Keep indexed logs for no longer than 365 days
Keep log files for an extra 365 days
No idea if that's possible and recommend asking TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 19 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY