Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
George_Ellis
Advisor
Jump to solution

What fields are indexed by the log indexer? Can it be modified?

Hi folks,

A lot of my work is validating rules and usage.  Almost all the time, I am using the Rule UID as part of the search string in the log search field.  Do we know if Rule UID is one of the indexes?  If not, do we know if there is a way to modify the indexer so it is included while indexing?

Problem space - I estimate we have well over 20TB of logs.  It takes longer to go though at least 60 days.

0 Kudos
1 Solution

Accepted Solutions
Amir_Senn
Employee
Employee

Hi,

The following sk shows what fields are being indexed:

https://support.checkpoint.com/results/sk/sk144192

Kind regards, Amir Senn

View solution in original post

0 Kudos
2 Replies
Amir_Senn
Employee
Employee

Hi,

The following sk shows what fields are being indexed:

https://support.checkpoint.com/results/sk/sk144192

Kind regards, Amir Senn
0 Kudos
George_Ellis
Advisor

I was searching for indexing and missed that.  So yes, already indexed.  As fast as it will go.  Sigh.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events