- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi Guys,
I am evaluating the logs in a 3600 device and came across quite a few errors recurring.
Does the error in the subject ring any bells ?
C3600> fw log -n -l
Error: Failed to read field product
31Oct2021 0:00:00 5 N/A 1 ctl cn=cp_mgmt,o=gw-9f7238..qtkfhz > daemon LogId: <max_null>; ContextNum: <max_null>; OriginSicName: cn=cp_mgmt,o=gw-9f7238..qtkfhz; log_sys_message: Log file has been switched to: 2021-10-31_000000.log;
Error: Failed to read field product_family
Below are the reference logs:
=========================
31Oct2021 0:00:00 5 N/A 3 accept cn=cp_mgmt,o=gw-9f7238..qtkfhz > eth1 LogId: 0; ContextNum: <max_null>; OriginSicName: cn=cp_mgmt,o=gw-9f7238..qtkfhz; inzone: External; outzone: Local; service_id: nbdatagram; src: 10.0.0.124; dst: 10.0.0.255; proto: udp; UP_match_table: TABLE_START; ROW_START: 0; match_id: 1; layer_uuid: 8a994dd3-993e-4c0c-92a1-a8630b153f4c; layer_name: Network; rule_uid: 60e2929c-4371-402b-bf57-3f2efca62cad; rule_name: Cleanup rule; ROW_END: 0; UP_match_table: TABLE_END; ProductName: VPN-1 & FireWall-1; svc: nbdatagram; sport_svc: nbdatagram;
Error: Failed to read field service
31Oct2021 0:00:00 5 N/A 4 drop cn=cp_mgmt,o=gw-9f7238..qtkfhz < eth1 LogId: 1; ContextNum: <max_null>; OriginSicName: cn=cp_mgmt,o=gw-9f7238..qtkfhz; TCP packet out of state: First packet isn't SYN; tcp_flags: FIN-ACK; src: 10.0.0.198; dst: 184.85.85.130; proto: tcp; ProductName: VPN-1 & FireWall-1;
Error: Failed to read field product_family
31Oct2021 0:00:00 5 N/A 5 accept cn=cp_mgmt,o=gw-9f7238..qtkfhz > eth1 LogId: 0; ContextNum: <max_null>; OriginSicName: cn=cp_mgmt,o=gw-9f7238..qtkfhz; inzone: External; outzone: Local; service_id: nbdatagram; src: 10.0.0.29; dst: 10.0.0.255; proto: udp; UP_match_table: TABLE_START; ROW_START: 0; match_id: 1; layer_uuid: 8a994dd3-993e-4c0c-92a1-a8630b153f4c; layer_name: Network; rule_uid: 60e2929c-4371-402b-bf57-3f2efca62cad; rule_name: Cleanup rule; ROW_END: 0; UP_match_table: TABLE_END; ProductName: VPN-1 & FireWall-1; svc: nbdatagram; sport_svc: nbdatagram;
Error: Failed to read field service
I see the error both in accept as well as drop rules ( cleanup rules) and would like to know why am I seeing this ?
Appreciate any directions here.
Best regards
Srini
Sounds like corrupted logs.
Recommend a TAC case.
Hi
We're aware of the issue. and working on a fix. The fix should be included in one of the upcoming JHFs.
Please check in the documentation for the relevant (upcoming) JHF to see if it is included in the list of resolved issues.
Hello, I'm having the same issue on R81 t36 mgmt server, when using 'fw log' the log messages have 'Error: Failed to read field product_family' and when grepping it's worse:
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
Error: Failed to read field product_family
21:35:15 5 N/A 15 accept > eth1 LogId: 0; ContextNum: <max_null>; OriginSicName: CN=xxxxxx,O=xxxxxx..xxxxxx; inzone: Internal; outzone: Internal; service_id:
<log info redacted>
15353;
Error: Failed to read field product_family
Same issue on R81.10 JHF Take 30
Similar symptoms (sk176644) appear to be resolved in the latest ongoing takes.
Still an issue in R81.10 Take 45.
Now I'm seeing this in fwd.elg with R81.10 JHF Take_45:
CJoinTableLogic::calculateJoinedFormat: error: can't find table: UP_action_table, field id: 201, in tables map
CJoinTableLogic::prepareLog fail to create joined format
write_log_fields_to_lea: error in format retrieval of log
Seems loosely related.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY