Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SubZer0
Contributor
Jump to solution

Are Logs Still Visible If Only the index File Remains?

On Check Point firewalls, two files are created for each log entry:

  • an index file
  • a log file

My question is:
If I manually delete the .log file but leave the index file on the firewall —
will the logs still be visible in SmartView Logs / Tracker?

 

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

The legacy SmartView Tracker only uses the .log file.
If the log file doesn't exist, neither do the log entries.

SOLR only indexes some of the fields in a log entry.
The contents of the "full log card" are in the .log file.
Which suggests you might see log entries in list views still, but "full log card" details won't be possible if you delete the underlying .log file.

Haven't tested this, personally, though.

View solution in original post

the_rock
MVP Gold
MVP Gold

The short answer is no. The logs wont be visible either in old shool SV tracker or logs if only index files remain, you 100% do need .log one as well.

Andy

View solution in original post

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The legacy SmartView Tracker only uses the .log file.
If the log file doesn't exist, neither do the log entries.

SOLR only indexes some of the fields in a log entry.
The contents of the "full log card" are in the .log file.
Which suggests you might see log entries in list views still, but "full log card" details won't be possible if you delete the underlying .log file.

Haven't tested this, personally, though.

the_rock
MVP Gold
MVP Gold

The short answer is no. The logs wont be visible either in old shool SV tracker or logs if only index files remain, you 100% do need .log one as well.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events