- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi there,
I am playing with cp_log_export on a r80.10 management server, and I notice the process does not start automatically when rebooting the server.
this mena I have to run cp_log_export start each time I reboot eh Server.
Is ti the normal behaviour? Or do I need to add something in the config?
Thanks
This happened to one of our customers too after an upgrade of Jumbo hotfix to take 272 which introduced log exporter plugin as part of the package instead of a separate plugin.
A portfix was provided on top of Jumbo take 272 to us which fixed the issue. As mentioned talk to TAC and they should provide it according to your current Jumbo
Try using "cp_log_export show" and look at your enabled value is true or false. True will start automatically with cpstart/mdsstart.
If false then you can set it by doing "cp_log_export set <name> enabled true [additional flag for mds]
Then restart it.
If this doesn't solve it please share.
Hello Amir,
The settigns seems to be ok
[Expert@gw-351389:0]# cp_log_export show
name: C3DEAMON
enabled: true
target-server: 192.168.1.10
target-port: 514
protocol: udp
format: syslog
read-mode: raw
If I run cpstop;cpstart, the log exporter is correctly restarted, but after a reboot i have the following:
[Expert@gw-351389:0]# cp_log_export show
name: C3DEAMON
enabled: true
target-server: 192.168.1.10
target-port: 514
protocol: udp
format: syslog
read-mode: raw
[Expert@gw-351389:0]# cp_log_export status
name: C3DEAMON
status: Not running
last log read at: 29 Jul 17:37:14
debug file: /opt/CPrt-R80/log_exporter/targets/C3DEAMON/log/log_indexer.elg
Recommend a TAC case here.
This happened to one of our customers too after an upgrade of Jumbo hotfix to take 272 which introduced log exporter plugin as part of the package instead of a separate plugin.
A portfix was provided on top of Jumbo take 272 to us which fixed the issue. As mentioned talk to TAC and they should provide it according to your current Jumbo
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY