Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
Legend Legend
Legend

SK144192 Updated With Which Log Fields are Indexed (and therefore searchable)

There have been frequent articles at CheckMates over the years complaining that when a seemingly valid search of indexed logs is performed in the SmartConsole, no matching results are returned even though the text searched for is clearly present in the log card.  The answer usually given in response is that the field in question was not "indexed" and therefore not searchable.  While one could poke about in the /opt/CPrt-R81.10/log_indexer/conf/LogFields.xml to determine which fields are indexed (thanks to @Vladimir for posing a question privately while he was writing his recent book that led to that discovery), the syntax of this file did not exactly make for easy reading.

As a result I submitted a request awhile back for sk144192: Description of Fields in Check Point Logs to be updated reflecting which specific fields are indexed, and also in which version they became indexed if they were not always so.  I'm pleased to report thanks to Sergei Shir that this update is now complete, which should make life a little easier for you frustrated log searchers out there:

indexed.png

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
5 Replies
PhoneBoy
Admin
Admin

Thanks @Sergei_Shir great info!

Wolfgang
Authority
Authority

Following Unable to find logs by filtering TCP state / TCP flag (checkpoint.com) some fields are indexed but you can't search.

Does someone knows this problem is fixed in one of the Jumbos for R81.10 or with R81.20?

0 Kudos
the_rock
Legend
Legend

If you provide specific search filter, happy to check in my R81.20 lab.

Andy

0 Kudos
Wolfgang
Authority
Authority

You can try filtering with the mentioned fields from the provided sk article. As an example the tcp state.

0 Kudos
the_rock
Legend
Legend

I dont think its any different in R81.20

 

Screenshot_1.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events