Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nadezhda
Contributor

SmartEvent storage depth

Logging of events on CheckPoint equipment is organized using SmartEvent server. Event log viewing is performed using the Security Management Server console (software versions on both serversR81.10). However, the event storage depth is no more than 2-3 days, which does not meet the current needs.

How can we increase the event storage depth on CheckPoint SmartEvent server to 15-30 days?

0 Kudos
6 Replies
G_W_Albrecht
Legend Legend
Legend

0 Kudos
Nadezhda
Contributor

Yes, we have seen that sk, thanks, but in $RTDIR/log_indexes we also contain logs longer than 3 days, so it probably doesn't fit for us

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Then ask CP TAC !

CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

I agree with @G_W_Albrecht ...if that sk does not help, TAC is your next avenue.

Andy

0 Kudos
Amir_Senn
Employee
Employee

Different indexes cores could have different definitions. You can check $FWDIR/conf/log_policy.C for advanced options. There's a chance that the logs are available but indexes are not, you can check it by trying to open log file manually of older dates and see if you can see the event in this mode (which is non-index mode).

Also, you should check log retention definitions on the SmartEvent server itself. If the server is short on storage it might trigger emergency log cleanup and might explain why this isn't available.

Kind regards, Amir Senn
0 Kudos
Chris_Atkinson
Employee Employee
Employee

What is the storage capacity / utilisation of the machine?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events