- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a few questions regarding Smartevent running on a Management HA setup (Smart-1 appliances).
Summary
Questions
It 'feels' like the views and reporting here isn't showing all of the GWs and wasn't sure if it was something missed here or if this not allowed by some design (i.e Smartevent required to be on its own server to see any other logs outside of "appliance A" here.
My past experience has been just standalone Smart-1 (no HA) or case where we had a standalone logger + Smartevent VM and a Management VM (which also was the secondary logger). Both cases i haven't seen any issues.
I wasn't sure if this is something I just need to provide some time to gather since we just activated it this a few hours back but wanted to make the ask now to see if there was any CP or community feedback known just in case 😉
Thanks in advance
In a Management HA environment, it is only supported to enable SmartEvent on the Primary.
A separate server is recommended.
See: https://support.checkpoint.com/results/sk/sk25164
In a Management HA environment, it is only supported to enable SmartEvent on the Primary.
A separate server is recommended.
See: https://support.checkpoint.com/results/sk/sk25164
1.1: No, SME will correlate logs from all the log servers you tell it to in the event policy.
2.1: Yes, the secondary needs an install database so it knows about SME being active on the primary.
Indeed, as answered above, the setup should work and SmartEvent should read the logs from the secondary MGMT (which is also a log server).
Also, Install DB is needed on both machines.
Another useful tip is that if you want to leverage both machines and spread the logs without manually defining groups of gateways that log to different servers, you can leverage the Log Distribution feature. It's a simple checkbox in the Logs page of the gateway object (where you set the log servers) and it will cause the gateway to "load balance" the log servers and split the logs between them. The balancing is automatic so if one server is too loaded, more logs will be sent to the other.
Also, if one log server goes down, all logs will automatically be sent to the other. In terms of capacity though, you need to make sure that one log server is sized to handle the entire estate, if you need to be able to function properly in case one server is down.
Ah....
On point #1, are you refering to within the smartevent console and going to "general settings => Initial Settings => correlation Units" and adding in the 2nd logger/management server?
Right now, its just the main logger/management where we installed Smartevent.
On #2, we did 'install database' on both during implementation. If #1 is correct, will that be required again or will it just require the publish of the smartevent policy?
If you're changing if SmartEvent is running on a given node, an Install Database is probably necessary.
Changing on where Smartevent is running is not concerned. The SK you provided earlier clarifies that....thank you 🙂
The concern I have to date is the lack of logs from the 2nd logger. The install of Smartevent and the correlated units took care of the main server. I just need to understand if the missing step mentioned on the 2nd one is where I am missing the piece.
From the logging guide and Smartevent, it mentions this portion that seems related to my issue:
*****
Open the SmartEvent GUI:
In SmartConsole > Logs & Monitor, click + to open a catalog (new tab).
Click SmartEvent Settings & Policy.
In Policy tab > Correlation Units, define a Correlation Unit object.
Select the production Log Servers and local Log Server on the SmartEvent Server to read logs from.
In Policy tab > Internal Network, define the internal Network.
Click Save.
Install the Event Policy
on the Correlation Unit:
SmartEvent menu > Actions > Install Event Policy.
*******
Under that Correlation units section today, i have the following after the initial install
| Correlation Unit | Log Server | Origin Type |
| Smart1-Main | Smart1-Main | Manually created |
Is this the case where I just need to 'edit' this one correlation unit and add the 2nd log server?
| Correlation Unit | Log Server | Origin Type |
| Smart1-Main | Smart1-Main, Smart1-Secondary | Manually created |
Yes you should add the second log server as a place to correlate logs from. You should be find to just do that and install the event policy to get that going, but an install database won't hurt anything.
Thanks 🙂
Its been updated and looks to be reporting properly now. That was the missing step 😉
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 39 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY