Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kozinka
Explorer
Jump to solution

Primary management - log server disconnected and just secondary management shows logs

Hello

Management Smart-1 625 R81.10 JHF95

My Primary management crashed because we wanted manualy reboot iDRAC - it was stucked (Management server un-plugged from eletricity). At the same time crashed CMOS battery (EoL). Management waked up to year 1998 -  I set up NTP, revoked all cp_mgmt certificates and generated a new one - SIC is established now with cluster (2 GWs) and with Secondary management too.

CMOS battery issue still persist - a new battery is on the way from Checkpoint support

Since CMOS battery crashed we have an issue with logging. Primary management does not show any logs.

Primary management - 10.16.34.70, when I logged in to smartconsole (10.16.34.70), opens logs there is a error:

LOG server is disconnected (10.16.34.70) - screens in the attachment

I tried everything from SK 40090 https://support.checkpoint.com/results/sk/sk40090

GWs have correct "masters" files

I tried cpstop moved $FWDIR/log/fw.log* to another folder and then cpstart - fw.log created and still increasing

I can open: open log file -> file -> fw.log from primary management and there are all the newest logs, refresh working

Last thing what I tried is upgrade to R81.20 with JHF T26 (both management servers) - primary management still shows LOG server is disconnected (10.16.34.70)

Can someone help me with this issue please?

Thanks

Marek

0 Kudos
1 Solution

Accepted Solutions
kozinka
Explorer

Hello,

I resolved this issue.

$RTDIR/log/RFL.log on the Security Management Server:

2023-10-02T11:31:46,446 WARN  [DefaultQuartzScheduler_Worker-4] com.checkpoint.rfl.SolrPerformanceMonitoringJob.execute:6 - <<== Threads Report: number of threads - 890 ==>>
2023-10-02T11:31:46,460 WARN  [DefaultQuartzScheduler_Worker-4] com.checkpoint.rfl.SolrPerformanceMonitoringJob.execute:1 - <<== Memory Report: Total Memory - 2048 MB; Used - 2008 MB, Free - 39 MB, Heap - 2008 MB, Non Heap - 82 MB, Percent Used - 98 %==>>

I found good Checkpoint script - /opt/CPrt-R81.20/scripts/doctor-log.sh and there was (screen in attachment)

Then I changed value for RFL_SOLR_MAX_HEAP:

$FWDIR/scripts/override_server_setting.sh -p RFL_SOLR_MAX_HEAP 8192

cpstop;cpstart

and DONE - logging WORKS again!! 🙂

View solution in original post

(1)
3 Replies
kozinka
Explorer

Hello,

I resolved this issue.

$RTDIR/log/RFL.log on the Security Management Server:

2023-10-02T11:31:46,446 WARN  [DefaultQuartzScheduler_Worker-4] com.checkpoint.rfl.SolrPerformanceMonitoringJob.execute:6 - <<== Threads Report: number of threads - 890 ==>>
2023-10-02T11:31:46,460 WARN  [DefaultQuartzScheduler_Worker-4] com.checkpoint.rfl.SolrPerformanceMonitoringJob.execute:1 - <<== Memory Report: Total Memory - 2048 MB; Used - 2008 MB, Free - 39 MB, Heap - 2008 MB, Non Heap - 82 MB, Percent Used - 98 %==>>

I found good Checkpoint script - /opt/CPrt-R81.20/scripts/doctor-log.sh and there was (screen in attachment)

Then I changed value for RFL_SOLR_MAX_HEAP:

$FWDIR/scripts/override_server_setting.sh -p RFL_SOLR_MAX_HEAP 8192

cpstop;cpstart

and DONE - logging WORKS again!! 🙂

(1)
the_rock
Legend
Legend

Wow, great job! 🙌👍

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events