- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello Checkmates,
there is the promlem and I cannot still understand what is the folder /dev/mapper/vg_splat_lv-log , which is mounted in /var/log/ resposible for?
There is a screenshot , where you can see that the /var/log/ folder is quickly filling.
During the last 7 days the usage has increased from 53% to 63%.
I guess that is a very rapid and anomaly behaviour.
Advise please how to solve this problem with quick filling.
Can I do something and solve this problem?
Thank you very much!
Or this very nice doku to add an disk:
https://community.checkpoint.com/message/32132-how-to-add-a-new-disk-and-expand-the-log-file-system
Thank you for a quick answer, but does that mean that all the files in that folder are necessary and we cannot remove some of them?
Yes, I've understood your very useful information, once again thank you!
or
find $FWDIR/log -type f -name '201*' -mtime +30 -exec rm {} \;
for such files older than 30 days
https://community.checkpoint.com/people/8221a355-5448-47cb-9c8a-d5f330a5909c - Nice one liner!
Comes into my CLI one liner collection!
This directory holds all logs. Logs from your gateways and all logs of your managementserver. Regarding the amount of your logged traffic this is normal behaviour. Extending the partion Heiko mentioned is the best solution.
Wolfgang
If the log is not filled up by normal logs, maybe a debug is running and forgotten to turn off?
So maybe some *.elg files permanently growing?
then
fw ctl debug 0
could help
Or if the files are vpnd.elg and ike.elg
vpn debug truncoff
could help
If it's just old log data, you ma delete the oldest if not needed.
Do you mean to use RemoveOldVersion.tar script by Check Point?
No, old logfiles. SMS is usually rotating logs renaming the old files using timestamp ath the beginning.
Just have a look at Heikos descriptions above
Thank you gentlemen!
I am going to try this approach.
Just make sure you do not delete logs you have to keep 🙂
I would rather suggest archiving those, sending to an external location via ftp or sftp and then remove
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY