Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FireMage
Explorer

import or export checkpoint logs to smartevent or syslog - R81.20

hello @All,

i have a problem with cp firewall logs. i have complete logs from 1/1/2023 in log directory on smartevent server. but i only see logs from mid march.

an offline import via the gui is not possible because of the amount of logs, the duration and also the work. the possibility via the log_indexer with -days_to_index 100 does not work either. i have now set up an elasticsearch v8 and could export the logs also in syslog format. new logs are already processed fine.

my question now:

how do i get the logs exported to smartevent or syslog again from 1/1/2023. the whole thing stupidly also with version R81.20.

thanks
jeff

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

When you say it didn’t work, what was the precise behavior?
Regardless, the only way to do this is with the procedure in: https://support.checkpoint.com/results/sk/sk111766
If this isn’t working as expected, please raise a TAC case: https://help.checkpoint.com

0 Kudos
FireMage
Explorer

hello phoneboy,

 

i have investigated to the log_indexer and i get a strange error in the log_indexer.elg:

[3955182400][12 Apr 17:41:22] LogFetcherLea::OnLeaAck: Added lea client filter for server [194.187.184.6].
[3980360512][12 Apr 17:41:25] Files read rate [adtlog] : Current=1 Avg=13 MinAvg=0 Total=67 buffers (0/0/0/12)
[4030716736][12 Apr 17:41:26] RFLIndexDoer::sendToSolr: I'm sleep
[4030716736][12 Apr 17:41:26] RFLIndexDoer::sendToSolr: SOLR error_type is - 1
[4030716736][12 Apr 17:41:26] SolrClient::Send: connection failure with 127.0.0.1:8210 (curl error: Failed to connect to 127.0.0.1 port 8210: Connection refused)(curl error number:7)

 

the log_indexer use port 8210 for connection, but in the settings.conf everything is ok:

(
:data ("/opt/CPrt-R81.20/log_indexer/data")
:server_port ("18244")
:dns_resolving (true)
:dns_backresolving (true)
:connections (
     :domain (
          :management (
               :name (127.0.0.1)
               :uuid ()
               :log_files (all)
               :is_local (true)
               :read_mode (CPMI)
          )
     :log_servers (
          : (
               :name (127.0.0.1)
               :uuid ()
               :log_files (all)
               :folder ("/opt/CPsuite-R81.20/fw1/log")
               :is_local (true)
               :read_mode (FILES)
               )
          )
)
)
:max_disk_space_usage (0)
:days_to_index (100)
)

 

what can i do?

thx

jeff

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events