- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
We are using CheckPoint MDS R80.10 running on VM. The VM has following parameters:
8 CPU Cores
32GB RAM
about 1TB Disk
We manage about 40 gateways and they generate about 200mln logs per day I guess because I see about 10 log files over 2GB size.
It works slowly especially when looking for logs.
I think that VM upgrade would help.
I have 2 questions:
1. What you would recommend in this situation?
2. Can I just add some CPUs/RAM to VM or I need to use special procedure for the upgrade like rebuild it or use different installation package?
Krzysztof
If you are not already using XFS consider switching over to it.
How many Domains/CMAs do you have? The more of these you have the more RAM and CPU cores you will need.
When running top during a busy period, what is the wio (waiting for I/O) percentage? If it is >10% that indicates a slow/saturated disk path which will cause performance issues no matter how many cores you add. Also before adding cores check your st (steal) percentage in top and sar as well, if it is nonzero you need to dedicate cores to your SMS VM in VMWare as it is not getting full usage of the 8 cores you already have from the hypervisor.
Just to give you some ideas for calculation 🙂
we get approx 250GB/day worth of logs on dedicated MLM. Our VM has 16 cores and 132GB memory.
Seems to work fairly OK with number of concurrent administrators.
And that's a dedicated log server. So if you run mgmt and logs on the same machine you probably want to increase RAM.
Plus get the latest take, ideally upgrade as there has been many fixes regarding Java heap sizes etc. We are on R80.20 T155
Thanks for the advice
I 've found that in normal situation the wa value is about 1% while when my colleague was watching on logs it increased to above 10% (maximum 16% I've seen). The st is always 0%.
But I've found load average was over 8% during that operation while normal is about 4%.
Krzysztof
Thanks for all advises. All are valid and I have following plan:
1. Upgrade current version to latest hotfix to increase stability and fix problem with Java according to sk123417 recommendations.
2. Upgrade VM according to CheckPoint response:
In general a VM should have twice the HW recommended on a physical appliance for the environment to match the actual computing power required
3. Check if the VM uses SSD disks and try to change it to SSD if possible.
4. Consider upgrade to newer version R80.30 or R80.40 to be able using XFS.
What do you think about it?
Krzysztof
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 12 | |
| 11 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Thu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY