- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi All,
I am getting below error when opening log files older than today. The logs are all blank as seen below. If we open any log, under Description i see "Could not open log file @A@@B@1539550560 on position:23167. Possible reasons: log-files were deleted, moved or have been corrupted."
Appreciate any input i can get on this.
Sounds like the log indexes might need to be rebuilt.
Did you open a TAC case on this?
Is there an SK I can refer to rebuild the index files. I have opened a case but so far they have only asked for cpu utilization and cpinfo from the devices.
I would advise checking the HDD space and log indexing threshold definitions before opening a TAC case.
A TAC case is opened already. HDD is used around 20%
I think the indexing threshold is set to delete index files older than 14 days.
Stick to support processes then. I am confident this will be resolved in no time. Please share the root cause when you get it fixed
Hi,
We were able to find the root cause of the issue.
We had recently added a SmartEvent server and configured the Management server to forward logs to the event server for correlation. As per sk106039 the logs are deleted after forwarding to the Event server and this is why we get the error in SmartLog.
We have not yet changed the forward_log_without_delete to true as per the SK. As a workaround we are choosing the SmartEvent server as the log source in SmartLog and clear the checkbox for the management server.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY