- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We recently replaced our open server hardware that was running the dedicated log server. I moved only the .log files (not other log files) from /var/log/opt/CPsuite-R81.20/fw1/log/2024-11-*.log to /var/log/opt/CPsuite-R81.20/fw1/log/ on another server ranging from 2024-11-1 to 2024-11-19.
I’m wondering how indexing works after this transfer. Does it happen automatically, or do I need to manually re-index the logs? I only need the last 14 days of indexed logs.
It seems like the article I found is relevant, but I wanted to confirm: is moving just the .log files sufficient, or should I have moved the other log files as well?
There are "pointer" files that are necessary for working with the logs (thus why the instructions state to copy $FWDIR/log/*.log* instead of $FWDIR/log/*.log.
I was mistaken that they are rebuilt automatically, you'd have to use fw repairlog (from the CLI) to do that.
As for whether the logs will get imported/indexed automatically, I would assume this would not be the case if you simply copied the files over.
Starting the reindexing process (as described in the SK) ensures this will be done.
The time will depend on the amount of logs, overall management/log server load, etc.
You will notice some increased CPU during this time, which will "back off" when other management processes need to use the CPU.
This is normal, expected behavior.
steps that I followed to resolve this issue:
Running sk111766 and then performing the below:
(I went through these steps but I am not sure if it fixed the issue. I was not seeing any indexed logs even after going through them)
The following steps actually started showing indexed logs in smart console.
Go to expert mode: fw repairlog -u 2024-11-15_032113_2226.log (you have to repair all the logs file that you want to repair)
After running fw repair log, I am seeing indexed logs. Thanks!
While I believe the log files alone are sufficient, the other files have to be rebuilt if they are not transferred.
It's better to move them all.
And yes, you will have to manually reindex the logs after moving files into the directory.
what does "rebuilt if they are not transferred mean"?
I just copied all the .log files and followed instruction from this sk artice:
https://support.checkpoint.com/results/sk/sk111766
I am not sure if it indexed logs or not. How can I verify that? How long does it generally take to re-index logs?
Don't forget, indexing the logs takes a while.
And don't forget evstop, and evstart. Ususallly thats why we don't apply this after upgrades. Is not worth the time.
Akos
There are "pointer" files that are necessary for working with the logs (thus why the instructions state to copy $FWDIR/log/*.log* instead of $FWDIR/log/*.log.
I was mistaken that they are rebuilt automatically, you'd have to use fw repairlog (from the CLI) to do that.
As for whether the logs will get imported/indexed automatically, I would assume this would not be the case if you simply copied the files over.
Starting the reindexing process (as described in the SK) ensures this will be done.
The time will depend on the amount of logs, overall management/log server load, etc.
You will notice some increased CPU during this time, which will "back off" when other management processes need to use the CPU.
This is normal, expected behavior.
steps that I followed to resolve this issue:
Running sk111766 and then performing the below:
(I went through these steps but I am not sure if it fixed the issue. I was not seeing any indexed logs even after going through them)
The following steps actually started showing indexed logs in smart console.
Go to expert mode: fw repairlog -u 2024-11-15_032113_2226.log (you have to repair all the logs file that you want to repair)
After running fw repair log, I am seeing indexed logs. Thanks!
Hello,
Is it possible, to import (copy) index files (audit, other, firewallandvp, smartevent) from backup and use them instead of waiting (for example a week) for reindexing? What are the requirements for this procedure (e.g. FetchedFiles modifications or anything like that)?
Regards
Mirek
And what that output from doctor-log means (after manual copying archive indexes):
"other_2025-07-13T00-00-00 should be transient, should have changed to transient after 30 days"
Maintenance Configuration:
Maintenance type : daily
Keep logs for : 730
Delete indexes older than: 365 days
In $INDEXERDIR/log_indexer_custom_settings.conf
:days_to_index (120)
In SMS Logs->Storage Daily Logs Retention Configuration:
Keep indexed logs for no longer than 365 days
Keep log files for an extra 365 days
No idea if that's possible and recommend asking TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY