Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Christoph
Collaborator

Critical: data loss risk – daily log ingestion might be capped! Update

Hello,

we are experiencing the same issue as MarcuzShinz in Solved: Critical: data loss risk – daily log ingestion mig... - Check Point CheckMates, where I stole the title from.

We have our management connected to the infinity portal and see the amount of ingested logs by the management server increased by 100%.

We double checked for incidents and see the following:

1. On prem SIEM logging reports the same or less number of events as the days before

2. Check Point Infinity Events shows the same or less number of events as the days before

3. Logfile size on the management server is the same or less as the days before

4. We checked a few customers and they all have this spike in log ingestion

This feels like a bug in the log ingestion accounting, unless some weird multi gigabyte data blob was sent to Check Point.

Cheers Christoph

 

 

 

 

0 Kudos
2 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Interesting observation, have you reported this to TAC for further investigation?

CCSM R77/R80/ELITE
0 Kudos
Christoph
Collaborator

Not yet. I will ask a colleague.

I opened a case now. Checked a few more customers and all of them that I checked have a spike yesterday, be it i.e. 4MB to 8MB or 25GB to 50GB. Will see what happens and if the results are the same for today.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events