- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: How to export all result for the SmartLog quer...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to export all result for the SmartLog query shows
Hi team:
We have one requirement for log export.
SmartLog query shows many entries when scrolling down. We want to export all these entries into one csv file.
But now we only can export about 200 entries even we have near 1300 searched entries.
Our SmartTracker only show the currently entries in the fw.log file. Is there any solution for this requirement?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartConsole will only export visible log entries.
SmartView will export up to a million entries (even if not visible).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk118002: Cannot export more than 50 records (logs) to Excel CSV in R80.XX
- Use SmartView on the web portal https://SMS_IP/smartview
- Use the legacy R80 SmartView Tracker application (CPlgv.exe) under folder C:\Program Files (x86)\CheckPoint\SmartConsole\R80\PROGRAM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Or change in SVTracker to the older log file and export the events file by file...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
I experienced the same issue a while ago. To be honest, it feels like a bug...
You can circumvent this issue by accessing the SmartView web application (https://mgmt_srv_ip/smartview).
Use the same syntax and export the logs within the web application - now the csv should contain all the logs and not just these that are shown on screen.
Regards,
Maik
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartConsole will only export visible log entries.
SmartView will export up to a million entries (even if not visible).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If we try to export it, its size is just in KBs and empty when we open it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You did try to export it from SmartView Tracker ? That should work: C:\Program Files (x86)\CheckPoint\SmartConsole\R80.10\PROGRAM\CPlgv.exe
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dameon Welch Abernathy Günther W. Albrecht
Yep, I tried with it but it is not showing the current logs as well. There is one more limitation in searching with SmartView Tracker that we can't search it for the Inline layer rules as this feature is in R80.x but Tracker is for R77.x.
Here is the detailed description which might help -
Symptoms:
============
Logs are Missing per rule
Steps Taken:
============
-Rule wise logs unable to generate the .csv file is getting crash
-While login to Security Policy->Logs->unable to see the logs intermittently.
Getting the error "no logs" .
-Confirmed that when generated log report from Smart View ->logs are missing and also informed that in legacy@@ smart tracker some of the rule logs are missing.
-#cpwd_admin list -all process are UP and running .
-Having enough disk space and memory verified #df -kh and free -m
-Its listening on port 257 verified #netstat -nap | grep 257
-#tcpdump -nnei any host <Firewall IP> and port 257
Firewall is sending logs to Management Server.
-#cpinfo -y all jumbo_take_112 installed on the appliance.
-#watch -d -n 2 "ls -l $FWDIR/log/fw.log" show the logs are storing on Management Server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would involve TAC here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does it have to enable log indexing for it? But I have a limitation of the hardware resources.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Assuming the operation involves multiple log files, I would assume so.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to export more than 1M logs? like all the logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To the best of my knowledge, no.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the past I escalated a service request to have this feature in R77.30 SC and I was very happy when it was added.
With R80.10 migration I was pretty disappointed when I noticed that this feature was gone again.
From my point of view SmartView can definitivly only be a workaround.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This feature is still not back (20th Feb. 2020).
Even in R77.30 it was working kind of slow...feeling as it could perform much better, but at least it worked.
Who would be able to make all the logentries visible beyond a thousand or so?? Honestly? Tedious! 😐
