- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: I can not see any audit log on Checkpoint FW R...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can not see any audit log on Checkpoint FW R81.10
When I checked the audit log ,there are not any logs for any times. How could it happen? Does Check Point delete audit log history? How can fix this ? Thank you so much for now.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your all kindly assistance. We resolved the problem with the reboot.🙈
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you revert to a previous revision recently?
How is the available storage space for the system?
Which Jumbo take is the system currently running?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have not an idea if it reverts to previous revision . I can see the currently revisions but I can not see details.
Take:78 in use.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you see any audit logs for previous time periods? Say if you search for something back in February or January? Your disk space is fine, so thats definitely not a concern.
Any clue when was last time this worked?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had chosen different times frame but unfortunately, there is no audit log.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you try Legacy SV Tracker ? If there also nothing is shown:
Connect to SMS using ssh and look into /var/log/audit/audit.log !
If no Audit logs are present, contact TAC ! According to https://support.checkpoint.com/results/sk/sk105805, Audit logs can be reduced but not disabled... Could be a FWM process issue (look at cpwd_admin list output).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the last audit log was on 29 Jan. After that there is no audit log into "/var/log/audit/audit.log".
According to sk105805, the options clicked on the system logging.
According to the command "cpwd_admin list," all services are up.
in the meantime,
I would like to share a correction which is the hotfix version take:78.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with @G_W_Albrecht , definitely contact TAC for this. Personally, I would install latest jumbo (take 87) and see what happens, but if no change, open a support case, for sure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
According to sk105805, Audit can not be disabled - so this is a new issue afaik. No harm in latest Jumbo install, but i fear it will not help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are probably correct, I also doubt it will help, but does not hurt to try.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take 82:
PRJ-42859,PRHF-26649
Security Management:
After performing the "Revert to Revision" operation, new Audit logs cannot be seen in the Logging&Monitoring View in SmartConsole.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your all kindly assistance. We resolved the problem with the reboot.🙈
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, whatever it takes to fix the problem...good job 👍
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you run a simple test, for example define a new Host and Publish and check to see if the Audit Log is created?
Can you also check various time frames in log query?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did but still no any log. It still says "no matches found for your search"
