Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
akurtasanov
Contributor
Jump to solution

Logs migration from old to the new SMS server

Good day.

Simple question.

It is enough to simply copy one $FWDIR/log folder from old server to the new for log migration?

P.s. Servers are equal in GAIA version. I know about indexes limitation.

0 Kudos
1 Solution

Accepted Solutions
G_W_Albrecht
Legend Legend
Legend

Just use migrate_server to migrate SMS including logs:

./migrate_server -v R8xxxx -l /<Full Path>/<Name of Exported File>.tgz

See https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

View solution in original post

9 Replies
_Val_
Admin
Admin

This was discussed multiple times in the community. Please look here: https://community.checkpoint.com/t5/Management/SmartLog-only-look-back-14-days-how-to-reindex-90-day...

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Just use migrate_server to migrate SMS including logs:

./migrate_server -v R8xxxx -l /<Full Path>/<Name of Exported File>.tgz

See https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
akurtasanov
Contributor

There is one problem.

Not enough free space for full migration.

lv_log total:800 used:627

Will be enough to create fully identical copy of log folder with, like this, command?
rsync -arvP /opt/CPsuite-R81.20/fw/log/ user@host:/opt/CPsuite-R81.20/fw/log/ --delete

0 Kudos
the_rock
Legend
Legend

Try delete some files from /var/log. Example...to check files bigger than 500M -> from expert mode, run -> find /var/log -size +500M

Andy

0 Kudos
akurtasanov
Contributor

There are not so many files. I assume around 10-15 gigs. Not enough.
I would like to avoid the process of increasing free space, but if creating an identical folder on both servers is not enough, then it seems worth going this route. 

0 Kudos
Amir_Senn
Employee
Employee

A few points:

  • You can set logging policy on your log server/ MGMT server. This will do maintenance on your logging by deleting older logs and indexes keeping only the amount of logs/indexes you need (daily maintenance performed on midnight) or by keeping at least X GB of free space on your logging partition (immediately).
  • Moving the logs manually will not let you search for logs out of the box. Indexer will only index logs files closed on the last 24 hours by default, so you will only have 24 hours of logs in index mode, the rest will be available by manually opening a log file (you can do it in the logs view) or be re-indexing them on the new server.
Kind regards, Amir Senn
0 Kudos
the_rock
Legend
Legend

Hey @akurtasanov 

What @G_W_Albrecht said is exactly what you need to do. -l flag is logs without indexing and -x is with.

Andy

Amir_Senn
Employee
Employee

@akurtasanov 

With x it's more recommended. No indexes migrated = need to open log files to search them. Or re-indexing.

Kind regards, Amir Senn
(1)
the_rock
Legend
Legend

Good to know!

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events