- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello everybody,
I would like to generate some security reports but I can generate reports with only 30 days retentions. I changed the option to do not delete the index files older than 30 days.
I follow the process as mentionned in the SK sk111766 and configured the ./log_indexer -days_to_index <NUM_OF_DAYS_TO_INDEX> to 90 days but nothing as changed when I generate a report.
If someone had the same issue and have find a solution ?
Regards,
Campos Miguel
Hello Dror Aharony,
Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.
I send you the result from the doctor-log.sh
Thank you a lot for your feedback
Miguel
Hello,
Where can I check that ?
The index file adds more space usage on top of the log files, so make sure you have enough free space available, or the oldest log will be deleted according to your policy.
Hello,
Yep, I already check this point, I have enough espace disk.
Regards,
Hi chico,
to Index older log-files up-to 90 days, you look to have configured it properly, assuming you restarted the Indexer (stopIndexer; startIndexer or evstop;evstart).
You definitely have enough space to avoid the 'emergency' min maintenance, more than 15% of Logs=/var/log/ partition (if I see it properly on your pic)?
if still doesn't work, Email me with output of:
$RTDIR/scripts/doctor-log.sh
Dror Aharony (drora@checkpoint.com)
Hello Dror Aharony,
Thank you for your reply, I'm just restarted the indexer service but nothing changed. I find an another SK for run SmartEvent Offline Jobs for multiple logs "sk98894" but I don't understand the difference with the SK sk111766.
I send you the result from the doctor-log.sh
Thank you a lot for your feedback
Miguel
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY