- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We have recently upgraded to R81.10 and I have restored the backup of the Log exporter . However, since the upgrade, the log exporter doesnt seem to be forwarding traffic on a constant basis. I can only see traffic on the logs that the log exporter is forwarding it about every 12 hours and it works when there is traffic seen (destination is receiving the data). Im trying to find where is the timing interval is configured as I cant see in the configuration what it sets up to.
I can now confirm that since running the command cp_log_export reconf and restarting the log exporter, this is now working as expected (frequent data sent instead of in batches). Thank you very much for all your responses.
Just to clarify are you using accounting with the rules or perhaps I don't understand the issue/symptom fully?
Refer:
https://community.checkpoint.com/t5/Management/Log-Accounting/m-p/107250
https://community.checkpoint.com/t5/Management/Log-tracking-and-account-timers/m-p/108010
Can you run cp_log_export show, check the target-server and target-port configured and then run a tcpdump to confirm the log server is sending traffic on the port to the target.
Where are you exporting to?
I ran the tcpdump and am not seeing constant traffic sent to the target. I see in on the firewall logs where the traffic to the target is hitting and this is matching the frequency being received by the target. Having said that, this wasnt the case prior to upgrade to R81.10. attached is the previous config and the current config of the log exporter
Hi!
Just found, that we have the same problem. We upgraded MDS from R80.30 to R81.10 and log_exporters are no more working.
EDIT: In our case, the reason was simply, that firewall in front of SIEM was blocking traffic from cma addresses. Previously rule had only mds main address as src.
The log exporter seems to stop sending traffic after some time. tcpdump doesnt show any output and when log exporter is restarted, it starts sending traffic again. When left out, it seems to start sending traffic at times and when it does it works just fine. I have logged a TAC case already and is being investigated by them . This is on R81.10 with JHF take 66 installed.
Hello,
I would like to understand how to try and reproduce your issue so we can investigate it. Can you please share some more details on your issue:
I have also tried running cp_log_export reconf and restarting the log exporter, it starts exporting data and then after a while, it stops again (tcpdump shows nothing )
Thank you. We'll try to reproduce the issue on our environment and investigate it. Just 1 more question to make sure: Are the exporters on MDS or MLM?
Thanks Arnon. I have just an update for this. I may not have ran the command "cp_log_export reconf" post upgrade but rather just restarted the log exporter (cp_log_export restart. so I ran the command again and restarted the log exporter. That seem to have now kept it going at a regular intervals now. Also, before this, the data being received contains all the logs so it seems to be just sending it in batches previously. This is now been resolved and seem to ssending it on a regular basis. Will observe this until tomorrow and confirm that its all rectified.
Thanks!
By the way - Are the exporters on MDS or MLM?
The exporters are in the Multidomain log server
Was there any change since your last update?
I can now confirm that since running the command cp_log_export reconf and restarting the log exporter, this is now working as expected (frequent data sent instead of in batches). Thank you very much for all your responses.
Thank you for the update!
Hi
I'll appreciate your response to Arnon's questions so we will be able to understand better the issue and try to assist.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
16 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY