> Source: [sk104321](https://support.checkpoint.com/results/sk/sk104321)

# sk104321 - When Threat Emulation sends files to emulation, SmartView Tracker logs show: "Threat Emulation ended with errors."

| Property | Value |
|----------|-------|
| Solution ID | sk104321 |
| Date Created | 2015-01-24 |
| Last Modified | 2015-05-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * A SmartView Tracker log is created with the following error:  
  "Threat Emulation ended with errors - Timeout was exceeded."
* The files are never added to the Threat Emulation queue.   

  # tecli show cloud queue   

* dlpu process debug shows the following errors:  

  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_av_create_file_upload_data: Failed to open file /opt/CPsuite-R77/fw1/tmp/dlp/{3342261C-210E-57D5-78DC-F2BBA490821B} for writing  
  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_av_free_file_data: freeing AV file data for file PartnerPortal.css  
  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_av_free_file_data: file_data-\>current_file_path/opt/CPsuite-R77/fw1/tmp/dlp/{3342261C-210E-57D5-78DC-F2BBA490821B}  
  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_av_free_file_data:: Failed to remove temporary file '/opt/CPsuite-R77/fw1/tmp/dlp/{3342261C-210E-57D5-78DC-F2BBA490821B}'.  
  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_init_session: \[A2E04\] Failed to create/add av session on connection. This transfer will NOT be scanned with DLP!  
  \[ 5219\]\[19 Jan 15:51:13\]\[DLPU_MNGR\] dlpu_mngr_http_session_free: freeing.. sid=5524215  

* The $FWDIR/tmp/dlp directory does not exist.

## Cause

The Threat Emulation infrastructure stores a copy of the file in a temp directory on the firewall.

When the directory does not exist, the process of sending the file to emulation fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
