> Source: [sk114616](https://support.checkpoint.com/results/sk/sk114616)

# sk114616 - FireWall logs from a Security Gateway arrive at the Management Server with a noticeable delay, and "Log buffer for tsid 0 is full" appears in the /var/log/messages file on the Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk114616 |
| Date Created | 2016-11-21 |
| Last Modified | 2022-09-29 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS) |

## Symptoms

- * FireWall logs from a Security Gateway arrive at the Management Server with a noticeable delay of more than several minutes, i.e., traffic was processed more than several minutes ago, but the log is displayed only now in SmartView Tracker.

* The */var/log/messages* file on the Security Gateway shows the following:

  * `FW-1: Log buffer for tsid 0 is full`
  * `fw_drv_ini: cpts_kalloc failed for FW_TSID_FWD (XXX)`
* Kernel debug ('`fw ctl debug -m fw + log`') on the Security Gateway shows the following:

  `;fw_send_kmsg: log buffer for tsid 0 is full.len = NNN;`  
  `
  ;fw_send_kmsg: log_first:XXX, log_last:YYY, free space:ZZZ ;`  
  `
  ;FW-1: fwloghandle_send_log: fw_send_trap failed;`  
  `
  ;Log was committed using the excessive mechanism.;`
* Debug of FWD daemon (per [sk86321](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86321)) on the Security Gateway does not show any output.

## Cause

The log buffer used by the FWD daemon is full. As a result, FireWall log messages are not processed in time.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
