- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Good day,
I searched and either it is not covered or my search sucked. I assume this is an "everybody knows that", but it is new to me.
I was chasing an issue with a potential false positive SNMP report to our collector. What is not important. I inspected /var/log/messages in Appliance 1 (from Orchestator "m 1 1"). When I went to appliance 2 and 3 ("m 1 2" and "m 1 3"), none of the files in /var/log were recent (2+ years old). Made me go "Huh?" It made some sense if you wanted to have 1 point to investigate. But considering dmesg also was ancient history, I started wondering.
Are the logs really consolidated on appliance 1, or they are somewhere else and I am missing it?
there are some possibilities.
keep in mind that could be cosmetic
Sorry, that is not the issue. That would have been easy. Time Date are correct, and there are some other files that are current like smart.log.dbg for example.
The logs are not consolidated on 1 device. You can use "asg log" command to query some logs across all cluster members. Viewing a Log File (asg log) You will probably see more current logs in your $FWDIR/log/* directories. My /var/log has some that haven't updated since last reboot, some since before that. There are a few with current timestamps in there though.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
2 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY