- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi
We are looking to migrate our current R80.30 MDM +MLM to R81.10 on new servers. I have tested with migrate_server export -v R81.10 -x <filename> on the MDM as a starting point but in R81.10 SmartConsole we see what appears to only go back to midnight of the previous day from when the migrate_server was run. How can we extend that back to include all traffic/audit logs?
Thanks
Hi,
Important note: You won’t be able to preserve log-Indexes (the actual SME log-DB), if you’re upgrading to R81.x from R80.x, as the Solr I/S had been upgraded.
so this procedure should only be done on R80.x to R80.x or R81.x to R81.x (like R80.20 to R80.40 or R81 to R81.10).
If upgrading to R81, then you can enlarge the indexing backwards time limit to index older logs/events - more than the default 1 day back (assuming the actual log-files from its Log-Servers still exist).
See sk111766.
If it's not possible for the log indexes, how about the raw log files after doing a logswitch and copy those over or is that not an option?
yes, this is an option since the log files are kept.
That's great! So all we'd need to do is copy over the old raw log files to the new server? Are they in the same format and don't need any sort of script to be run to be able to be read by R81.10? If we do that could we also then also follow the SK you mentioned to index the additional days as well?
No need to copy. The log files should have already been imported as part of the migrate server as you have shown above (-x / -l).
Yes, same format - all good. Then you can follow the sk111766 to re-index back as many log files days of data as you wish.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY