CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 3 of 3

Thread: Smartlog slow to return results

  1. #1
    Join Date
    2005-11-22
    Posts
    2
    Rep Power
    0

    Default Smartlog slow to return results

    How fast should i expect to see results on searches? I always thought it was touted that I could look through billions of logs quickly.

    Currently, our SmartLog server shows 1,028,744,775 logs over a 7 day period of time (October 3 - October 10). That does seem to be inline with the fact that we've set it to only index 7 days worth of logs. However, when I do a query for something and it has to search through all 7 days worth of logs to find (or not) what I was looking for it takes several minutes. We're talking over 20+ minutes to get through all logs. Obviously, if it finds something more current like in today's logs those results come back first but if it requires finding something that may have happened several days ago then the search takes forever. I guess that it is faster than me opening all these individual logs files and doing searches via SmartTracker, but still.

    Does anyone else have a massive amount of logs and this is the case? Should I just live with it and hope that I only really need to do searches for current date and time?

  2. #2
    Join Date
    2014-09-02
    Posts
    377
    Rep Power
    10

    Default Re: Smartlog slow to return results

    I think the first question you'll get from most is about the hardware specs. Yes, SmartLog can be very fast to return results, even with your numbers. However, running on under-powered gear can easily make for a less-than-stellar (bad) experience.

    So, before we look further, what can you tell us about CPU, RAM, disk speed, etc. (of the log server)?


    -E

  3. #3
    Join Date
    2006-09-26
    Posts
    3,200
    Rep Power
    20

    Default Re: Smartlog slow to return results

    Quote Originally Posted by EricAnderson View Post
    I think the first question you'll get from most is about the hardware specs. Yes, SmartLog can be very fast to return results, even with your numbers. However, running on under-powered gear can easily make for a less-than-stellar (bad) experience.

    So, before we look further, what can you tell us about CPU, RAM, disk speed, etc. (of the log server)?


    -E
    You should definitely look into kibana: https://www.elastic.co/products/kibana. It can use LEA to collect checkpoint log

    I can search through 5 billions records in less than 45 seconds.

Similar Threads

  1. DNS Return Traffic being blocked
    By gojericho0 in forum Topology Issues
    Replies: 3
    Last Post: 2016-04-16, 17:29
  2. Upgrade to R75.10, with SSDs, from R65; Results
    By alienbaby in forum Provider-1 (Multi-Domain Management)
    Replies: 1
    Last Post: 2011-08-19, 00:56
  3. Filter returns no results
    By boldin in forum SmartView Tracker
    Replies: 6
    Last Post: 2010-01-22, 15:16
  4. Hello... I've been lurking.. time for something in return
    By AdamBarton in forum Introductions
    Replies: 0
    Last Post: 2009-03-11, 12:02
  5. Connection established .... no return traffic
    By Kheiron in forum SecureClient/SecuRemote
    Replies: 3
    Last Post: 2008-02-06, 20:35

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •