CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-12
Laurent Mercier Laurent Mercier is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 4
Rep Power: 0
Laurent Mercier has an average reputation (10+)
Default LEA OPSEC

Hi everybody,

I am trying to use the product loggrabber (hxxp://sourceforge.net/projects/fw1-loggrabber) to make a
real-time analysis of the logs of our firewall (Firewall-1 NG FP3).
Everything seems ok, but when we execute the command "fw logswitch", on the FW1 management server, loggrabber doesn't receive any more data from the management server.

If we kill Loggrabber et restart it, everything works well.

Have you ever meet this kind of trouble?

Thanks.

Laurent
Reply With Quote
  #2 (permalink)  
Old 2006-01-12
SamuelB SamuelB is offline
Junior Member
 
Join Date: 2005-12-30
Posts: 7
Rep Power: 0
SamuelB has an average reputation (10+)
Default Re: Lea Opsec

Laurent,

Please keep in mind that I have not used loggrabber before. What version of loggrabber are you using? The latest version 1.11.1 mentions the following note:

*A bug in Checkpoints OPSEC SDK, which causes a segmentation fault of fw1-loggrabber when switching logfiles on the management station, made it necessary to relink the binaries. Additionally there are minor bugfixes in this release.

This seems to be the issue that you have described.

Thanks,
Samuel
Reply With Quote
  #3 (permalink)  
Old 2006-01-13
Laurent Mercier Laurent Mercier is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 4
Rep Power: 0
Laurent Mercier has an average reputation (10+)
Default Re: Lea Opsec

Thanks a lot Samuel,

Effectively,my version of loggrabber is: fw1-loggrabber-1.11.1. I have found
an hotfix (http://www.opsec.com/cp_products/90.htm), hotfix 4 - Linux, which may solve this problem. I am going to test it.

Thanks again.

Laurent
Reply With Quote
  #4 (permalink)  
Old 2006-01-16
Laurent Mercier Laurent Mercier is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 4
Rep Power: 0
Laurent Mercier has an average reputation (10+)
Default Re: Lea Opsec

Hi everybody,

On the site www.opsec.com, I have downloaded the files

- OpsecSdkNgFp3Hf4.linux22.tar.gz
- OpsecSdkNgFp3.linux22.tar.gz

in order to solve my problem (with Loggrabber)

But does anybody know how to install this hotfix. The installation discribed
in OPSEC_SDK_FP3_HF4_RN.pdf is not very clear.

Thanks

Laurent
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:03.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0