- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Dear Team
What are the log specification when setting up mgmt-HA with two Smart-1 appliances?
I thought there was no log when Smart-1#1 stopped, but when I tried it, there was a log when Smart-1#1 stopped, and it was the same as Smart-1#2.
The logs have been accumulating in SecureGateway for a while, and will they be synced when Smart-1#1 comes up, or is the log also synced from Smart-1#2?
Where the logs go is controlled by the settings per the screenshots above.
When management is unavailable the gateway will attempt to retain logs locally for as long as capacity allows until such time as connectivity is restored.
If the configuration is sending to both, the logs will be available on the Secondary to be accessed whilst primary is down.
What logging options do you have configured in the gateway object and which component versions are used?
Thank you for the reply.
Is this where the logging options are set?
You can configure your gateways to send the logs to both management hosts. If doing this, all logs are available at the same time on both nodes. If you configure a backup log host, the logs are send only to this host if the primary is not available.
Will be disk storage no problem on both nodes I would prefer sending all logs to both nodes everytime.
Thank you for the reply.
With this setup, I think that the logs when the primary is down don't remain in the primary, is this understanding correct?
Your question is unclear but the logs are not removed from the primary no.
Thank you for the reply.
First of all does mgmt-HA have log synchronization feature?
If the SecureGateway is set to send logs to two amart-1 appliances , how will the logs be processed while the 1 Primary unit is down?
Is the log sent only to the Secondary? Is the log sent from the SecureGateway when the Primary is starting?
Where the logs go is controlled by the settings per the screenshots above.
When management is unavailable the gateway will attempt to retain logs locally for as long as capacity allows until such time as connectivity is restored.
If the configuration is sending to both, the logs will be available on the Secondary to be accessed whilst primary is down.
Thank you for the reply.
I understood that the logs are also accumulated in SG and supplemented when the connection of primary that is down is restored.
Can this supplementation period be adjusted?
.Of course, we recognize that logs are being contiune to sent to Secondary, which is not down, even while primary is down.
It depends on available disk space and the configured thresholds for the same.
Thank you for the reply.
I want to know that is not the thresh holds of the disk, the time cycle of SMS and SG log synchronization.
Is there a limit to syncing log?
For example, if Primary is stopped for 3 days, only the last 2 days will be reflected. etc
Again it is based on storage space not time since each environment is different in terms of log rates/volumes.
Generally more free space equals longer retention.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 21 | |
| 19 | |
| 12 | |
| 8 | |
| 8 | |
| 8 | |
| 7 | |
| 6 | |
| 5 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY