Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
InfrasecConsult
Participant
Jump to solution

Management server not showing logs from a new Cluster, logs from another Gateway is working

Management server not showing logs from a new Cluster however the logs from another Gateway connected to the same Management is working correctly.

I followed sk40090 and cannot find any issue.

I can do a Policy install, SIC is working, Logging is correctly configured in the Gateway Cluster object, the Master file is correct on the Gateways, etc.

Doing a TCPdump on both the Gateway and simultaneously on the Management server for port 257 , I can see the logging connections on both the Gateway and the Management server.

Checking the size of the log file on the Gateway also shows it's not increasing in size.

There is enough space on the Management disk, and the other Gateway still sends logs which is visible in the logviewer.

I did a Database install on the Management Server, no change. Even went so far as to do a CPSTOP/CPSTART on the Management.

The Management server and the Gateways are on the same subnet. 

Both the Gateways and the Management server are on R81.20 Take 26

The Gateways are on 5100 appliances and the Management is on a VM "Open Server"

Any other ideas what could be wrong?

0 Kudos
1 Solution

Accepted Solutions
InfrasecConsult
Participant

The issue of not seeing the logs in the Logviewer for the newly added Cluster is now resolved.

 I enabled "log Indexing" yesterday on the Management Object and this morning when I checked I can see all logs (From the new Cluster and the original Gateway)

Not sure why however. 

View solution in original post

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

If you use "fw log" on the CLI, do you see logs from the other cluster?

0 Kudos
InfrasecConsult
Participant

The issue of not seeing the logs in the Logviewer for the newly added Cluster is now resolved.

 I enabled "log Indexing" yesterday on the Management Object and this morning when I checked I can see all logs (From the new Cluster and the original Gateway)

Not sure why however. 

0 Kudos
Amir_Senn
Employee
Employee

For general reference,

1. reading logs on without indexing is limited to a specific GW on a specific log file. With indexing you can see all the logs that were sent to the log server and from multiple log files.

2. If the management server is the log server then when adding new GWs is updated well but when using a dedicated log server you will need to perform "Install database" on the log server so it will get the information about the new GWs.

 

Kind regards, Amir Senn
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events