Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
sx8n20394
Collaborator

Logging broken in R82.00.10 Build 998002242

We upgraded to build 2242 and experienced many issues in which I detailed in a previous post. I wanted to bring light to this issue in this separate post.

After upgrading I noticed the following:

1. We no longer see any inbound Accept/Deny/Drop logs in the GUI. This affects both local GUI and Infinity Portal log GUI. We can see the drops when using the CLI.

2. Most, if not all,  URL Filtering and Application Control logs are completely blank. See below:

Screenshot 2026-07-15 103205.png

We added this to our current support request but wanted it to be publicly known.

3 Replies
jorgeluiznim
Advisor

 

Hello, @sx8n20394 

Thank you for reporting this issue and for sharing your observations after upgrading to R82.00.10 Build 998002242.

I have a lab environment available and I'll reproduce this scenario using the same software build to verify whether I can observe the same logging behavior or whether it appears to be specific to your environment.

I recently performed several tests using this release and encountered a few issues, however I don't recall seeing the specific symptoms you described regarding:

  • Missing inbound Accept / Drop / Deny logs in the WebUI.
  • Blank URL Filtering and Application Control log entries.

I'll validate these behaviors in my lab and I'll get back to you with my findings as soon as possible.

Additional Information Required

Before drawing any conclusions, could you please let me know which Quantum Spark appliance model you're using?

This information is important because Check Point introduced different upgrade paths and platform restrictions for R82.

  • If you're using a previous-generation Pro appliance (15xx / 1600 / 1800 / 1900 / 2000 Series), there are known upgrade considerations documented by Check Point, including changes to CoreXL allocation during cluster upgrades and specific supported upgrade paths.
  • Could you please let me know the exact appliance model (for example, 1555, 1800, 1900, 2570, etc.), I'd prefer to continue investigating before recommending any software changes. If I can reproduce the issue in my lab—or if we collect enough technical evidence—we can determine whether this behavior requires further investigation by Check Point TAC.
My next steps
  • Deploy the same build (R82.00.10 Build 998002242) in my lab.
  • Verify inbound logging (Accept / Drop / Deny).
  • Validate URL Filtering and Application Control logging.
  • Compare the results with your environment.
  • If necessary, gather additional diagnostics before escalating to TAC.

Relevant Check Point Documentation

SK184492 - Spark Firewall Pro Models - R82 Upgrade Restrictions

This article explains which appliance models support R82, the supported upgrade paths, and the firmware restrictions for Quantum Spark Pro appliances.

https://support.checkpoint.com/results/sk/sk184492
SK184478 - Spark Firewall Cluster Upgrade to R82.00.10

Describes a known behavior affecting cluster upgrades on specific appliance models where CoreXL CPU allocation changes after the upgrade, potentially causing temporary failover or HA interruptions until both cluster members are upgraded.

https://support.checkpoint.com/results/sk/sk184478
Quantum Spark R82 Administration Guide - Backup, Restore, Upgrade and Other System Operations

Provides the official firmware upgrade procedures, supported upgrade paths, rollback options, and references to the upgrade restrictions documented in the SK articles above.

https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/AdminGuides_Locally_Managed/E...

 

Once I complete the validation in my lab, I'll update you with the results so we can determine whether this is a reproducible software issue or an environment-specific behavior.

Best regards,
Jorge Luiz

0 Kudos
sx8n20394
Collaborator

This is a 2560. If this is a one off issue, it wouldn't surprise me because we had 2 other 2560's have random issues the TAC could not reproduce and required factory resets.

0 Kudos
jorgeluiznim
Advisor

Unfortunately, I had a similar case with a 2530 where I had to roll it back to R82.00.05 Build 998000913 to resolve the issue.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events