- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: maximum days to index the offline logs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
maximum days to index the offline logs
we had some issue after upgrade https://support.checkpoint.com/results/sk/sk111766 same as the mentioned sk.
here i would like to know what is the maximum number of days logs we can index ? can we plan for 365 days ?
and is there any method to read the logs which are exported to local PC ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The main issue with indexing 365 days worth of logs is disk space and the time it'll take.
I believe it should work, though.
Check Point log files are in a proprietary format.
You can "print" them using fw log and/or CpLogFilePrint and/or export them with fwm logexport.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The main issue with indexing 365 days worth of logs is disk space and the time it'll take.
I believe it should work, though.
Check Point log files are in a proprietary format.
You can "print" them using fw log and/or CpLogFilePrint and/or export them with fwm logexport.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any method to read those exported logs ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
when Smart - 1 is in HA , is it matter where we reindex the first ? either on primary or secondary ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In index mode we can query all the servers at once, so as long as you query all the servers that can function as log servers it doesn't matter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
so, can we reindex logs on primary first and then to secondary ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There's no need to index more than once, it asks all the selected log servers at once.
Indexes are created from the logs on the same machine they're stored on, to index them on another server is to copy them and change number of days to index to include range of logs. If you want log redundancy you can do that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All three tools I mention produce ASCII text output, just in different forms.
