- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Mates,
Long story short, I had a smartEvent VM taking dust in R80.10, still configured in a R77.30 old CMA not in use anymore.
I’ve upgraded the VM in R81.10 and configured it in a new CMA (also in R81.10) as specified in the documentation https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/To... .
First, I couldn’t install the policy but the sk https://support.checkpoint.com/results/sk/sk113127 helped with it.
Now, policy is installed but I have the error message below while looking for the logs:
And in the CMA, the smartEvent object is in error with this message: “Error (CPSEMD not running)”
Management seems up and running on the VM, and the SmartEvent blades enable:
[Expert@SmartEvent:0]# /opt/CPsuite-R81.10/fw1/scripts/cpm_status.sh
Check Point Security Management Server is running and ready
[Expert@SmartEvent:0]# evconfig
Please select the installation you would like to update
1) SmartReporter. (disabled, select to enable)
2) SmartEvent Server. (enabled, select to disable)
3) SmartEvent Correlation Unit. (enabled, select to disable)
4) SmartEvent Intro. (disabled, select to enable)
5) SmartEvent Intro Correlation Unit. (enabled, select to disable)
Tried cpstop/cpstart and reboot but I keep having the error. cpsemd.elg is spammed with the messages below:
[CPSEMD 13615 4054460480]@SmartEvent[5 Feb 14:38:08] CDBConfiguration::RefreshStatus() - Failed to calculate available DB max size.
[CPSEMD 13615 4054460480]@SmartEvent[5 Feb 14:38:13] CRFLStatusFetcher::HandleResultFailed - CRFLStatusFetcher::HandleResult() - The reply from RFL is empty (status: 0)
Do you have a clue on what could be wrong with CPSEMD ?
Thanks!
Thank you all for your feedback.
The only drop I had was on the TCP/8211 port between the SmartEvent and the CMA. To the best of my knowledge, the port is not listed on the CheckPoint documentation so I hadn't opened it until now... and it works, logs are now collected by the smartEvent.
The port 8211 is mentioned in the comment on this thread too, so it seems to be needed for the smartEvent to work https://community.checkpoint.com/t5/Security-Gateways/R8x-Ports-Used-for-Communication-by-Various-Ch...
Now my quest continues, with the queries failing in the view/reports as show below:
I see core dump for the SOLR process:
[Expert@SmartEvent:0]# ls -l /var/log/dump/usermode/ | grep solr
-rw-rw---- 1 admin root 197655728 Feb 6 10:47 solr.23729.tar.gz
-rw-rw---- 1 admin root 409921130 Feb 6 10:35 solr.32750.tar.gz
I tried to disable and enable again log indexing (mentionned in this thread https://community.checkpoint.com/t5/Management/Database-Smartevent-Query-Failed/td-p/8630) but it doesn't change much.
I'll keep looking 😁
If you come from an ancient version you need to make sure that the new ports are allowed by the policy.
CPSEMD is for logging into the GUI.
I agree with @Lesley , sounds like config issue to me, specially if you did cpstop/cpstart and reboot.
Best,
Andy
Thank you all for your feedback.
The only drop I had was on the TCP/8211 port between the SmartEvent and the CMA. To the best of my knowledge, the port is not listed on the CheckPoint documentation so I hadn't opened it until now... and it works, logs are now collected by the smartEvent.
The port 8211 is mentioned in the comment on this thread too, so it seems to be needed for the smartEvent to work https://community.checkpoint.com/t5/Security-Gateways/R8x-Ports-Used-for-Communication-by-Various-Ch...
Now my quest continues, with the queries failing in the view/reports as show below:
I see core dump for the SOLR process:
[Expert@SmartEvent:0]# ls -l /var/log/dump/usermode/ | grep solr
-rw-rw---- 1 admin root 197655728 Feb 6 10:47 solr.23729.tar.gz
-rw-rw---- 1 admin root 409921130 Feb 6 10:35 solr.32750.tar.gz
I tried to disable and enable again log indexing (mentionned in this thread https://community.checkpoint.com/t5/Management/Database-Smartevent-Query-Failed/td-p/8630) but it doesn't change much.
I'll keep looking 😁
Thats why Im thinking TAC may need to help you further if you are getting core dumps generated.
Best,
Andy
Try to make the scope smaller (1 hour). Now you are requesting data that is not there. This because logging only started to work recently.
Just to let you know that the last issue, "query failed", fixed itself after a few days when SOLR process stopped crashing.
TAC recommanded to change the heap size value just in case the issue occurs again if there is too much logs to handle.
Hello Mates,
Long story short, I had a smartEvent VM taking dust in R80.10, still configured in a R77.30 old CMA not in use anymore.
I’ve upgraded the VM in R81.10 and configured it in a new CMA (also in R81.10) as specified in the documentation https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Deploying-SmartEvent.htm?tocpath=Getting%20Started%7C_____4 .
First, I couldn’t install the policy but the sk https://support.checkpoint.com/results/sk/sk113127 helped with it.
Now, policy is installed but I have the error message below while looking for the logs:
And in the CMA, the smartEvent object is in error with this message: “Error (CPSEMD not running)”
Management seems up and running on the VM, and the SmartEvent blades enable:
[Expert@SmartEvent:0]# /opt/CPsuite-R81.10/fw1/scripts/cpm_status.sh
Check Point Security Management Server is running and ready
[Expert@SmartEvent:0]# evconfig
Please select the installation you would like to update
1) SmartReporter. (disabled, select to enable)
2) SmartEvent Server. (enabled, select to disable
...Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 18 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY