Thats it Don! Never tried that command, but super useful, thank you!
@Garrett_DirSec . check out the output from my lab
[Expert@CP-MANAGEMENT:0]# CPLogInvestigator
Thank you for using log investigator tool.
==============================================================
Start reading log file: /opt/CPsuite-R82/fw1/log/fw.log
Start reading log file: /opt/CPsuite-R82/fw1/log/fw.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-13_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-13_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-12_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-12_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-11_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-11_000000.log from log 0
...
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-10_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-10_000000.log from log 0
....
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-09_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-09_000000.log from log 0
....
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-08_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-08_000000.log from log 0
...
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-07_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-07_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-06_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-06_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-05_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-05_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-04_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-04_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-03_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-03_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-02_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-02_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-01_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-11-01_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-31_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-31_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-30_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-30_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-29_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-29_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-28_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-28_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-27_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-27_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-26_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-26_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-14_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-14_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-13_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-13_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-12_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-12_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-11_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-11_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-10_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-10_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-09_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-09_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-08_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-08_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-07_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-07_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-06_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-06_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-05_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-05_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-04_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-04_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-03_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-03_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-02_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-02_000000.log from log 0
..
Reading log file is DONE.
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-01_000000.log
Start reading log file: /opt/CPsuite-R82/fw1/log/2025-10-01_000000.log from log 0
..
Reading log file is DONE.
Total scanned 3205706 logs out of 3205706 logs in file
Scanned logs dates are from 30-09-2025 00:00:00 to 13-11-2025 08:42:03
Observed blades:
- Anti Malware
- Application Control
- IPS
- N/A
- New Anti Virus
- URL Filtering
- VPN-1 & FireWall-1
========================================
Summary - Estimations based on findings:
Log file size per day: 0.6457GB (72193 logs)
Estimated events per day:
- Estimated events per day based on active blades: 1295
Storage required per day:
- SmartEvent: 0.0060GB
- Log Server: 0.6457GB
- Log Server + SmartLog: 1.2913GB
Please refer to sk87263 to use these metrics and size your SmartEvent solution. The SK can be found at Check Point▒s Support Center :
https://supportcenter.checkpoint.com/supportcenter/index.jsp
==============================================================
Best,
Andy