- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We recently replaced an R77.30 management server with R80.10. Since then our configured log rotation schedule is being ignored. We have it set to rotate firewall log files on Tues and Thurs at 11pm, but it's *also* rotating the log files at every midnight. Is this a new "feature"? (If so, it doesn't exist in any documentation anywhere.) Can it be over-ridden? I want no more than two log files per week.
Thanks
This was discussed in a previous thread: Disabling the built-in Logswitch on R80 SMS at midnight?
It's also confirmed in the following SK: R80.x Security Management/Log Server runs logswitch nightly at 12:00:00 AM
SK119794 is literally the only place this behavior is mentioned. It's not included in the Security Management Admin guide, the Logging and Monitoring Admin guide, the R80 intro (sk108623), the R80 Known Limitations (sk108624), nor in any of the logging kb articles I can find. Even though it apparently affects all versions 80.x, it went completely undocumented from R80's release in March of '16 until sk119794 was published in Aug. of '17.
That's rather disappointing.
While I agree this could have been documented sooner, I am curious about the specific use case where only two log files a week is desirable.
Note that by default, all logs are indexed in R80.x, which reduces the need to reference a specific log file, such as was required with SmartView Tracker.
Tracker is sometimes preferable to SmartLog. Twice weekly is simply a good balance for us between query speed and having relevant/recent log entries available. In addition, our data retention policies require us to separately archive firewall logs for 60 days. It's easier to manage eight log files/month than 30. I'd prefer four, but they get unwieldy large.
Understand that while the binaries for SmartView Tracker are still included in R80 and R80.10, it has been deprecated and may be removed in a future release.
If there is specific functionality that you can't achieve in SmartLog R80.x, it's worth a separate thread to discuss.
I have just upgrade our Provider-1 to R80.10 and I had discovered this topic.
Reading SK119794 I assume there is a logswitch at midnight ¿and/or at 2Gb?
On the other hand, we are storing logs for at least 2 years due to legal requirements.
If SmartView Tracker may be removed in a future release, which could be the best practice to store logs?
Yes, we auto-switch at midnight and/or 2GB, whichever comes first.
You can still archive the logs the same way as with previous releases (i.e. copy off the files from $FWDIR/log) and they can be read in and reindexed.
Dameon,
I noticed this behavior was also occurring on Audit logs now, can you disable those separately?
1 audit file is mostly more than enough per Domain.
These log rotations cannot be disabled to the best of my knowledge.
I'm certain that there are intermediate cases but I have a use case where any log switching at all is unnecessary and inconvenient - CMAs which don't receive traffic logs. These can go for years without the .adtlog getting too large.
I'm here because I have a script which reports on policy install operations etc and now will have to enhance it to determine which files to iterate over for a given period.
... unless it's possible to query SmartLog from the command line?
Logs are currently not queryable through the CLI.
If you want to see when the gateway last received a policy (either through fetch or push), the command cpstat -f policy fw (from the gateway) will tell you.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY