- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello everyone,
I need to export the results of a query related to a specific (access) log file from last year (2022).
When I open this file in Check Point Manager, I am able to perform the query and view the results. However, I am not able to export them to .csv format since this functionality has been migrated to the web version of SmartView.
Nevertheless, when I try to use the web version of SmartView, I cannot find any possible location to manually upload this file and then proceed to perform the query and export to .csv.
Could someone kindly provide any ideas on how to achieve this without having to submit this file for reindexing proccess?
I appreciate your attention and support.
Thank you.
You should be able to do it from the command line. fwm logexport -i <input file> -o <output file> -- don't forget to get a -n switch in there somewhere to skip the reverse lookups. More detail here: https://support.checkpoint.com/results/sk/sk118519
What is the file extension?
Andy
I have transfered the specific set of a specific log to the /opt/CPsuite-R81.20/fw1/log directory (please see below):
-rw-r--r-- 1 admin root 2097153968 Aug 28 14:08 2022-03-25_093617_349.log
-rw-r--r-- 1 admin root 161 Aug 28 14:08 2022-03-25_093617_349.log_stats
-rw-r--r-- 1 admin root 80 Aug 28 14:08 2022-03-25_093617_349.logaccount_ptr
-rw-r--r-- 1 admin root 25628328 Aug 28 14:08 2022-03-25_093617_349.loginitial_ptr
-rw-r--r-- 1 admin root 60092456 Aug 28 14:08 2022-03-25_093617_349.logptr
Then I can open (in SmartConsole client Version) the file "2022-03-25_093617_349.log" and I can query it... But I am not able to export the query results...
And I am not able to open it in the web version, because there´s no 'open' menu in that...
Happy to test it in my lab if you are allowed to send the file.
Unfortunately, I am not.
Anyway, the main question is: Is there a way to manually import/load an old log file using the web version of SmartView?
(Thanks anyway)
To import, no. But, as I mentioned in my last post, you can try use date range option to find those logs and then export them.
Andy
This date range option doesn´t seem to work for this or any other older file that hasn´t been (re)indexed....
Understood. Sorry mate, I got nothing else then. Maybe TAC can give you an official statement, but Im 99.99% sure you cannot import log file into smartview.
Andy
No problem... Anyway, I appreciate the support and attention! I´ll try them.
No worries. Maybe someone else here will know...there are way smarter people on here than me, so lets see if anyone comes through : - )
Andy
Actually, I have a suggestion. How about if you click in smartview where it says last 24 hours, then search by date range and sere if you can find those logs and then export into csv format?
Andy
Yes... This is working fine... I can query and export the recent (and already indexed) files. But not the old ones.
SmartView does not allow you to upload log files.
The only way I know of to access a specific log file is to have log indexing disabled.
SmartView will allow you to access log files in $FWDIR/log in this situation.
Not sure you should disable this on your production SMS but you could build a lab one in a VM where this is disabled (in the management object).
Thank you for your response!
I believe that due to language barriers, I probably couldn't make myself clear in describing my question. I apologize for that.
In fact, I'm using a lab SMS.
I then transferred an old log file to the $FWDIR/log directory.
From there, when I enter SmartConsole and connect to this SMS, I can open the log file (see attached screenshot) and perform some queries from this newly (old) loaded file.
However, I'm unable to perform the export to .CSV, as this functionality has been migrated to the web version of SmartView.
On the other hand, when I access the web version of SmartView on this SMS , I can't use the "File - Open Log" menu because it simply does not exist. So I am not able to open this old log file. Because of this, I can't perform the necessary queries, and consequently, I can't export the .csv file (simply because I couldn't even open the log file in the web version of SmartView).
The great paradox is:
a) When I use the combination of SmartConsole client + SMS, I can open an old log, but I can't perform the export.
but...
b) When I use the combination of SmartView web + SMS, I might be able to export to .csv, but I can't do it because I simply can't open an old log file.
The point is: I didn´t want to reindex... I just wanted to open an old log file, query it and export the query results.
Sorry for the long text/explanation.
You should be able to do it from the command line. fwm logexport -i <input file> -o <output file> -- don't forget to get a -n switch in there somewhere to skip the reverse lookups. More detail here: https://support.checkpoint.com/results/sk/sk118519
Good call @Lloyd_Braun , never thought of that 👍
Andy
Good morning, everyone.
Thank you for the information! I ran the test here with the 'logexport' command and it worked. It's worth mentioning a few 'features': There's no way to previously apply a filter, so you end up generating a rather large file. As a result, converting a 2 GB file takes a quite reasonable amount of time... and, lastly, dealing with a 2.XX GB .txt file is not a straightforward task with regular tools. But... it works.
I appreciate everyone's support!
Thanks for clarifying.
I think your best bet is the fwm logexport command, as mentioned by @Lloyd_Braun
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
6 | |
4 | |
4 | |
4 | |
4 | |
2 | |
2 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY