CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-18
Degsy Degsy is offline
Junior Member
 
Join Date: 2006-10-18
Posts: 4
Rep Power: 0
Degsy has an average reputation (10+)
Default Can't view logs older than 2 days in SmartView Tracker

Hi there

First post so be gentle!

I have around 28GB of firewall logs on the management server yet in SmartView Tracker, the log only displays back to the previous day.

Is it possible to view all logs (or run a query) in the one window?
Reason I ask is i need to check when a certain Client VPN user connected but I don't know when it was last connected.

I don't have Eventia Reporter licenced so not sure if this would solve my problem.

Doing my NGX I & II courses next week so should be more up to speed then.

Any help appreciated.

Running CP NGX R60

Cheers
Degsy
Reply With Quote
  #2 (permalink)  
Old 2006-10-18
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 810
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Can't view logs older than 2 days in SmartView Tracker

You've probably got your logs being rotated regularly - a good strategy. If they were one 28GB file, it would be extremely slow to search through it.

You can open previous log files (file -> open), but that will replace your current view. The current filter will be applied.

Searching for when remote users last logged in can be a real pain. If you're doing third party authentication, it's easier, but Check Point isn't really set up for it.

You could, I suppose, export all the logs to text files, and search them, but it would take a long time and a lot of diskspace.
Reply With Quote
  #3 (permalink)  
Old 2006-10-20
Degsy Degsy is offline
Junior Member
 
Join Date: 2006-10-18
Posts: 4
Rep Power: 0
Degsy has an average reputation (10+)
Default Re: Can't view logs older than 2 days in SmartView Tracker

Yes the logs are rotated at midnight each day.
Well i guess my only option is to use the "search in file" function in Windows Explorer across all files and then open only those files with positive results.
Thanks for the prompt reply northlandboy!
Reply With Quote
  #4 (permalink)  
Old 2006-10-20
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 894
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Can't view logs older than 2 days in SmartView Tracker

For whatever it's worth, we had to be able to look at remote user logins easily due to Sarbanes-Oxley audit requirements. We bought a SmartView Reporter R56 license and it's made things like this wonderfully easy.

It automatically aggregates all logs into a single MySQL database. I cna hold a year's worth of logs in about 22 GB. Oddly, that's a lot less than the individual log file sizes.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0