Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Juan_Manuel_Bri
Participant

Not getting logs under "LOGS AND MONITORING"

Hi, i´m having problems on SMS to get the log´s from my firewall´s, I was having some problems with the DB and needed to restore it SMS and import the DB from one of my working BK´s. the thing is that since a restore it we are getting error message from the JPEG under LOGS & MONITOR. Can u help me with a some tips so i can fix this issue. The thing is that when i use smartview tracker im able to retrieve the logs from all my firewall.error message

4 Replies
Jerry
Mentor
Mentor

check the cpwd_admin list if:

* the cpd and fwm process is running

* the MFSERVER process is there

see if the elg files appears in $CPDIR/log and $FWDIR/log directories - see their date

also, I would have checked the DB integrity as well as use DBGEDIT from Windows PC if you have a proper communication with it in general

if you manage multipy FWs please check in MGMT in each object if LOG servers are defined, see if they're also definied in Management SMS

there is plenty of other things to consider but first things first Smiley Happy

Jerry
0 Kudos
Jerry
Mentor
Mentor

do you see files like those in bold on your SMS?

[Expert@cp:0]# pwd
/opt/CPshrd-R80/log
[Expert@cp:0]# ls -l
total 109224
-rw-r--r-- 1 admin config 280085 Dec 12 2017 cp_conf.elg
-rw-r--r-- 1 admin root 1173 Jun 28 2017 cpapache_postinstall.elg
-rw-rw-r-- 1 admin root 5011879 Aug 19 22:26 cpd.elg
-rw-rw-r-- 1 admin root 20971603 Aug 10 10:21 cpd.elg.0
-rw-rw-r-- 1 admin root 20971610 Jun 27 07:11 cpd.elg.1
-rw-rw---- 1 admin users 20971621 May 14 08:42 cpd.elg.2
-rw-rw-r-- 1 admin root 20971565 Mar 30 10:14 cpd.elg.3
-rw-rw-r-- 1 admin root 20971573 Feb 14 2018 cpd.elg.4
-rw-r--r-- 1 admin root 382551 Aug 19 17:14 cprid.elg
-rw-r--r-- 1 admin root 4482 Aug 18 20:43 cprid_wd.elg
-rw-rw---- 1 admin root 7205 Aug 18 20:46 cpstart.log
-rw-rw---- 1 admin users 3664 Aug 19 12:15 cpview_stats_live
-rw-rw---- 1 admin root 725143 Aug 19 22:22 cpwd.elg
-rw-rw---- 1 admin root 94 Jun 28 2017 fw1_components.log
-rw-r--r-- 1 admin config 351348 Aug 19 20:47 hservice.elg
drwxrwx--- 2 admin root 4096 Jun 28 2017 log
-rw-rw---- 1 admin root 0 Jun 28 2017 mpclient.elg
-rw-rw---- 1 admin root 14486 Aug 18 20:44 mpdaemon.elg
-rw-rw-r-- 1 admin root 859 Sep 21 2017 postgresqlcmd.elg

also, check your cpwd_admin list for:

DBWRITER

RFL

LPD

those are also important components of log-server processing

I assume that your SMS is VM isn't it? or is it Smart-x ?

Jerry
0 Kudos
Juan_Manuel_Bri
Participant

Hi Jerry

Thanks for the troubleshooting tips. My SMS is a VM. Let me run the

commands and i let you know the results in a moment.

Regards

On Sun, Aug 19, 2018, 2:29 PM Jerry Szpinak <donotreply@checkpoint.com>

0 Kudos
Juan_Manuel_Bri
Participant

Hi Jerry

This is whta I see with the " cpwd_admin list" command on me SMS:

# cpwd_admin list

APP PID STAT #START START_TIME MON COMMAND

CPVIEWD 3792 E 1 3/8/2018 N cpviewd

CPD 3804 E 1 3/8/2018 Y cpd

FWD 3888 E 1 3/8/2018 N fwd -n

FWM 3891 E 1 3/8/2018 N fwm

SOLR 4104 E 1 3/8/2018 N java_solr

/opt/CPrt-R80/conf/jetty.xml

RFL 4140 E 1 3/8/2018 N LogCore

SMARTVIEW 4161 E 1 3/8/2018 N SmartView

INDEXER 4196 E 1 3/8/2018 N

/opt/CPrt-R80/log_indexer/log_indexer

SMARTLOG_SERVER 4319 E 1 3/8/2018 N

/opt/CPSmartLog-R80/smartlog_server

CPM 4334 E 1 3/8/2018 N

/opt/CPsuite-R80/fw1/scripts/cpm.sh -s

DASERVICE 4435 E 1 3/8/2018 N DAService_script

CPSM 31277 E 1 3/8/2018 N cpstat_monitor

LPD 5004 E 1 15/8/2018 N lpd

I do not see MFSERVER and DBWRITER. I have check the Solution ID sk97638

but i get the error that the path dosent exist when i run the command

cvpnstart.

Here are the files that are under $CPDIR/log

# cd $CPDIR/log

# pwd

/opt/CPshrd-R80/log

# ls -l

total 87836

-rw-rr 1 admin config 84569 Aug 9 15:36 cp_conf.elg

-rw-rr 1 admin root 1173 Feb 27 09:30 cpapache_postinstall.elg

-rw-rw-r-- 1 admin root 17428 Jul 30 09:14 cpconfig.elg

-rw-rw---- 1 admin root 396851 Aug 19 21:37 cpd.elg

-rw-rw---- 1 admin root 20971602 Aug 18 16:30 cpd.elg.0

-rw-rw---- 1 admin root 20971551 Jun 27 15:09 cpd.elg.1

-rw-rw---- 1 admin root 20971609 May 21 14:29 cpd.elg.2

-rw-rw---- 1 admin root 20971554 Apr 7 23:28 cpd.elg.3

-rw-rr 1 admin root 97619 Aug 3 13:19 cprid.elg

-rw-rr 1 admin root 1464 Aug 3 13:18 cprid_wd.elg

-rw-rw---- 1 admin root 6903 Aug 3 13:19 cpstart.log

-rw-rw-r-- 1 admin root 200 Aug 3 13:29 cpview_stats_live

-rw-rw---- 1 admin root 201476 Aug 19 21:36 cpwd.elg

-rw-rw---- 1 admin root 94 Feb 27 09:27 fw1_components.log

drwxrwx--- 2 admin root 4096 Feb 27 09:27 log

-rw-rw---- 1 admin root 5071475 Feb 27 10:52

migrate-2018.02.27_10.37.26.log

-rw-rw---- 1 admin root 0 Feb 27 09:27 mpclient.elg

-rw-rw---- 1 admin root 0 Feb 27 09:27 mpdaemon.elg

-rw-rr 1 admin root 1357 Jul 30 22:12 postgresqlcmd.elg

#

Here are the files that are under $FWDIR/log

# cd $FWDIR/log

# ped

bash: ped: command not found

# pwd

/opt/CPsuite-R80/fw1/log

# ls -l

total 6514144

-rw-rw---- 1 admin root 11041 Aug 19 00:00

2018-08-19_000000.adtlog

-rw-rw---- 1 admin root 80 Aug 18 00:00

2018-08-19_000000.adtlogaccount_ptr

-rw-rw---- 1 admin root 120 Aug 19 00:00

2018-08-19_000000.adtloginitial_ptr

-rw-rw---- 1 admin root 160 Aug 19 00:00

2018-08-19_000000.adtlogptr

-rw-rw---- 1 admin root 1124348537 Aug 19 00:00

2018-08-19_000000.log

-rw-rw---- 1 admin root 161 Aug 19 00:00

2018-08-19_000000.log_stats

-rw-rw---- 1 admin root 80 Aug 18 17:57

2018-08-19_000000.logaccount_ptr

-rw-rw---- 1 admin root 22660892 Aug 19 00:00

2018-08-19_000000.loginitial_ptr

-rw-rw---- 1 admin root 51342864 Aug 19 00:00

2018-08-19_000000.logptr

-rw-rw---- 1 admin root 2145395246 Aug 19 11:05

2018-08-19_110522_36.log

-rw-rw---- 1 admin root 162 Aug 19 11:05

2018-08-19_110522_36.log_stats

-rw-rw---- 1 admin root 80 Aug 19 00:00

2018-08-19_110522_36.logaccount_ptr

-rw-rw---- 1 admin root 43807896 Aug 19 11:05

2018-08-19_110522_36.loginitial_ptr

-rw-rw---- 1 admin root 98840256 Aug 19 11:05

2018-08-19_110522_36.logptr

-rw-rw---- 1 admin root 2145392824 Aug 19 19:48

2018-08-19_194855_37.log

-rw-rw---- 1 admin root 162 Aug 19 19:48

2018-08-19_194855_37.log_stats

-rw-rw---- 1 admin root 80 Aug 19 11:05

2018-08-19_194855_37.logaccount_ptr

-rw-rw---- 1 admin root 41450684 Aug 19 19:48

2018-08-19_194855_37.loginitial_ptr

-rw-rw---- 1 admin root 95948464 Aug 19 19:48

2018-08-19_194855_37.logptr

-rw-rw---- 1 admin root 12288 Feb 27 12:31 BVUuidDB

-rw-rw---- 1 admin root 4 Aug 10 13:44 actlog.time

drwx

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events