| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi, I recently upgraded from R55 to R62. since then, audit logs are empty. Doing a logswitch or even deleting everything in the LOG directory (after cpstop then cpstart) doesn't help. I then decided to upgrade to R65 but the issue still remains. Note: All other logs from the gateways can be seen in the Tracker but the audit logs remains empty even after creating objects and saving the change. Can someone help me, please? |
| |||
| Edit: I missed where you specified 'Audit' log before I posted. I had an issue with logs in general so disregard if this is not your situation. I had this issue years ago also when going from NG R55p to NGX R60. In my case (and a few others I've seen posted here) the issue was with NAT between the gateways and the SCS (as in CP Auto-NAT). It has to do with what addresses are listed as Primary in SCS (public vs private). I ended up creating another CP object and defining it as a log server only. If your issue turns out to be NAT, there are other ways to do this and I recall seeing this subject before on these forums. If I'm not mistaken, someone even quoted a KB article, if you search a little, you should find it. __________________ There's no place like 127.0.0.1 Last edited by lammbo; 2008-01-23 at 08:54. |
| |||
| Thanks Lammbo, but I think you are referring to Firewall logs, whereas my issue is to do with Audit logs which tracks what admin (s) have been doing on the Smartcenter (i.e creating objects, pushing policy, etc.). |
![]() |
| Thread Tools | |
| Display Modes | |
| |