- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have an environment where the SmartCenter Server and Log Server have been upgraded from R80.40 to R81.10 through CPUSE. I have not been part of the CPUSE upgrade, and thus don't know what was (or was not) done at the moment of the upgrade.
It has later been noticed that logs older than 5-6 days prior to migration are missing from the Logs & Monitor. I've followed sk111766 and tried to re-index the logs for past 30 days, but I still get no traffic logs.
Any recommendation on how to find and retrieve old logs on the management server and/or log server, and show them in Logs & Monitor in SmartConsole?
Thanks,
Daniel
This is documented in the R81.10 Known Limitations:
R81 includes new logs indexing mechanism, so when upgrading Management server/Log Server/Multi-Domain Server/Multi-Domain Log Server/SmartEvent from R80.x, old log indexes are not upgraded.
The indexing mechanism will re-index the last 24 hours automatically. To increase the period of offline indexing (how far in the past to re-index the logs), see sk111766.
This is documented in the R81.10 Known Limitations:
R81 includes new logs indexing mechanism, so when upgrading Management server/Log Server/Multi-Domain Server/Multi-Domain Log Server/SmartEvent from R80.x, old log indexes are not upgraded.
The indexing mechanism will re-index the last 24 hours automatically. To increase the period of offline indexing (how far in the past to re-index the logs), see sk111766.
Hi @PhoneBoy ,
Thanks for your reply! I understand that it is a known issue, what I was struggling with was with the actual re-indexing.
Yesterday I followed the steps in SK111766 on both Management Server and Log Server but saw no change in SmartConsole. It seems that I needed to just wait for it to do it's magic over night, checking SmartConsole Logs & Monitoring today did confirm that following SK111766 helped with the issue.
[Expert@xxxxxx:0]# more log_indexer_custom_settings.conf
(
:data ("/opt/CPrt-R81.10/log_indexer/data")
:server_port ("127.0.0.1:18244")
:dns_resolving (true)
:dns_backresolving (true)
:connections (
:domain (
:management (
:name (127.0.0.1)
:uuid ()
:is_local (true)
:read_mode (CPMI)
)
:log_servers (
: (
:name (127.0.0.1)
:uuid ()
:folder ("/opt/CPsuite-R81.10/fw1/log")
:is_local (true)
:read_mode (FILES)
)
)
)
)
:max_disk_space_usage (0)
:days_to_index (30)
Depending on the volume of logs, the reindexing can take some time.
Further, to not impact the other management server functions, the indexing takes place at lower priority.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY