There have been frequent articles at CheckMates over the years complaining that when a seemingly valid search of indexed logs is performed in the SmartConsole, no matching results are returned even though the text searched for is clearly present in the log card. The answer usually given in response is that the field in question was not "indexed" and therefore not searchable. While one could poke about in the /opt/CPrt-R81.10/log_indexer/conf/LogFields.xml to determine which fields are indexed (thanks to @Vladimir for posing a question privately while he was writing his recent book that led to that discovery), the syntax of this file did not exactly make for easy reading.
As a result I submitted a request awhile back for sk144192: Description of Fields in Check Point Logs to be updated reflecting which specific fields are indexed, and also in which version they became indexed if they were not always so. I'm pleased to report thanks to Sergei Shir that this update is now complete, which should make life a little easier for you frustrated log searchers out there:
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com