Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nadezhda
Contributor

SmartEvent storage depth

Logging of events on CheckPoint equipment is organized using SmartEvent server. Event log viewing is performed using the Security Management Server console (software versions on both serversR81.10). However, the event storage depth is no more than 2-3 days, which does not meet the current needs.

How can we increase the event storage depth on CheckPoint SmartEvent server to 15-30 days?

0 Kudos
6 Replies
G_W_Albrecht
MVP Silver
MVP Silver

0 Kudos
Nadezhda
Contributor

Yes, we have seen that sk, thanks, but in $RTDIR/log_indexes we also contain logs longer than 3 days, so it probably doesn't fit for us

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

Then ask CP TAC !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
MVP Gold
MVP Gold

I agree with @G_W_Albrecht ...if that sk does not help, TAC is your next avenue.

Andy

0 Kudos
Amir_Senn
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

Different indexes cores could have different definitions. You can check $FWDIR/conf/log_policy.C for advanced options. There's a chance that the logs are available but indexes are not, you can check it by trying to open log file manually of older dates and see if you can see the event in this mode (which is non-index mode).

Also, you should check log retention definitions on the SmartEvent server itself. If the server is short on storage it might trigger emergency log cleanup and might explain why this isn't available.

Kind regards, Amir Senn
0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

What is the storage capacity / utilisation of the machine?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events