Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Daily log ingestion


Am i the only one?
I see that start to happening in other customer as well.
Daily log ingestion .png

0 Kudos
1 Solution

Accepted Solutions
Tomer_Noy
Employee
Employee

Indeed, your daily log ingestion is exceeding your quota.

You can get more information about your quota and ingestion patterns in the Log Ingestion Dashboard of the Infinity Events application.
Here's a screenshot from a demo tenant:

Log Ingestion Dashboard.png

You can see your ingestion over time, and split by applications (if you have more than one).

You can also leverage Infinity Events to identify "noisy" rules that generate a lot of logs, then switch them to "Session Logs" or deactivate logging on them (if appropriate).

These SKs have lots of useful information on this:
https://support.checkpoint.com/results/sk/sk182394 
https://support.checkpoint.com/results/sk/sk181096 

View solution in original post

8 Replies
_Val_
Admin
Admin

Are you over the quota?

0 Kudos
the_rock
Legend
Legend

You need license for bigger quota.

0 Kudos
RemoteUser
Advisor

got it thanks

PhoneBoy
Admin
Admin

Depending on the exact service and SKUs you've purchased, there are limits to the amount of logs that can be ingested.
We only started enforcing this earlier this year which is why you are seeing the message now.
This either requires reducing the log volume or purchasing the appropriate SKU to update the limits.

0 Kudos
RemoteUser
Advisor

thanks you @PhoneBoy 

0 Kudos
Tomer_Noy
Employee
Employee

Indeed, your daily log ingestion is exceeding your quota.

You can get more information about your quota and ingestion patterns in the Log Ingestion Dashboard of the Infinity Events application.
Here's a screenshot from a demo tenant:

Log Ingestion Dashboard.png

You can see your ingestion over time, and split by applications (if you have more than one).

You can also leverage Infinity Events to identify "noisy" rules that generate a lot of logs, then switch them to "Session Logs" or deactivate logging on them (if appropriate).

These SKs have lots of useful information on this:
https://support.checkpoint.com/results/sk/sk182394 
https://support.checkpoint.com/results/sk/sk181096 

RemoteUser
Advisor

thank you so much for the explanation, very satisfying!

the_rock
Legend
Legend

Thats great place to check, indeed.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events