> Source: [sk102043](https://support.checkpoint.com/results/sk/sk102043)

# sk102043 - FWM process is down due to oversized fwm.adtlog file

| Property | Value |
|----------|-------|
| Solution ID | sk102043 |
| Date Created | 2014-08-24 |
| Last Modified | 2015-02-01 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |

## Symptoms

- * FWM process is down due to oversized fwm.adtlog file
* Output of fwm -d shows:  
  \[FWM ...\[21 Jul 11:43:43\] CFwdCommStreamLocal::Write failed to send 477 bytes  
  \[FWM ...\[21 Jul 11:43:43\] Deleting page at 0 address 227009208  
  \[FWM ...\[21 Jul 11:43:43\] CLogFile::Open: Smart fflush enabled in log file  
  /bin/fwm_start: line 6: 29561 File size limit exceededfwm "$@"
* In case the issue re-occur please take FWD debug and search for: WARNING: could not create listen socket for "localhost" FATAL: could not create any TCP/IP sockets In case you see those lines that means, that FWD which responsible for the audit logs, failed to write audit logs From the FWM process. As backup FWM will write audits to FWDIR/conf/fwm.adtlog. Usually when FWM connects to FWD, we resend audits and clear fwm.adtlog. In this case FWD failed to bind on port 1024, and fwm.adtlog reached 2GB.

## Cause

The fwm.adtlog file, located under $FWDIR/conf, is 2GB in size, and it is causing FWM to fail to start.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
