Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
fjulianom
Advisor

How to verify logs and log indexing

Hi everyone,

 

My customer MDS suddenly started losing logs some months ago. It was a problem related to the disk space, it seems the MDS didn't delete old logs, and when the disk was full, it started to lose the current logs. We opened a TAC case, and for solving the problem in some way, customer created a script for maintaining the disk space low and not losing logs. Yesterday, customer told me the MDS suddenly started again to work fine about the logs again, the disk space was reduced, and indexing started to work fine again. We don't know the reason yet. But, apart from the root problem, how can I verify logs and log indexing is working fine? What files do I have to check? Sorry but I am kind of newbie in Check Point.

 

Regards,

Julián

0 Kudos
4 Replies
Lesley
Leader Leader
Leader

I am getting triggered by this:

"customer created a script for maintaining the disk space low and not losing logs."

What is this script and why? The system should automatically cleanup old logs if configured correctly.

I would recommend moving away from this customer script and check the settings here:

SmartConsole -> Relevant SmartCenter mgmt object -> Logs -> Local Storage

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
PhoneBoy
Admin
Admin

The Doctor Log script mentioned here might be useful: https://support.checkpoint.com/results/sk/sk181782 

fjulianom
Advisor

Hi guys,

 

The problem is not easy. As said, I opened a case to TAC and didn’t find the root cause. They created a fix and it didn’t work, so my customer had to find a temporal solution. TAC continues investigating. But as said, I didn’t open this thread to investigate the root cause of the issue, because first, TAC is on it (I hope), and second, customer told me is solved (suddenly it appeared, and suddenly it disappeared). Then, apart from the root problem, do you know how can I verify logs and log indexing is working fine right know? What files do I have to check? I have no idea. Please your help.

 

Regards,

Julian

0 Kudos
the_rock
Legend
Legend

The sk Phoneboy gave is super useful.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events