> Source: [sk111766](https://support.checkpoint.com/results/sk/sk111766)

# sk111766 - SmartEvent Server does not index / does not show logs older than 1-14 days

| Property | Value |
|----------|-------|
| Solution ID | sk111766 |
| Date Created | 2016-05-31 |
| Last Modified | 2024-11-30 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * After an upgrade of the SmartEvent / SmartLog Server to the version R80 (or higher), or after import of log files to the SmartEvent / SmartLog Server R80 (or higher), it shows logs only for the last 1-14 days (since the date of the upgrade/import).

* The `$RTDIR/log_indexes/` directory on the SmartEvent / SmartLog Server contains directories that go back only for the last 1-14 days (since the date of the upgrade/import).

* If you run a SmartEvent offline job, the events appear on the **Events** tab, but not on the tabs of specific Software Blades.

* If you run a SmartEvent offline job to send historical log files to a SmartEvent server, the "`Files`" read as "`DDD MM DD HH:MM:SS 1969`" (e.g., `Wed Dec 31 18:00:00 1969`) and show "`0`" for the number of logs.

## Cause

By default, SmartLog / SmartEvent Server R80 and higher indexes and shows logs only up to 1-14 days back (counting back from the date of the upgrade/import).

Notes:

* Starting from R80.20, only one last day is indexed by default (the `fw.log` file and all log files in the last 24 hours).  

* Steps from the article [sk164553](https://support.checkpoint.com/results/sk/sk164553) may be required if the issue started after an upgrade.  
  The solution procedure below will not work properly if the files that need to be re-indexed are already listed as indexed as per the "`FetchedFiles`".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
