> Source: [sk116122](https://support.checkpoint.com/results/sk/sk116122)

# sk116122 - "Query resolution failed. Logs might not display properly. Try again later" error in SmartLog

| Property | Value |
|----------|-------|
| Solution ID | sk116122 |
| Date Created | 2017-02-28 |
| Last Modified | 2026-08-04 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server, Logging & Status |
| Versions | R82.10, R82, R81.20, R82.10, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R81.20, R81.10 (EOS), R81 (EOS), R82 |
| OS | Gaia |

## Symptoms

- * "Query resolution failed. Logs might not display properly. Try again later." message when running a query: ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1488259311628/empty_rows1702272133.png)

* The SmartConsole may also show the error, "There are no allowed log servers, check your log server configuration"  

*
    * Scenario 1 additional symptoms:  
    Show / Hide symptom  

    * Blank rows in SmartLog (logs are empty and have no data) after restoring the MDS backup.

    * Scenario 2 additional symptoms  
    Show / Hide symptom  

    * Security Gateways are configured to send logs to the Security Management server as well as to a log server.
    * Security Management server/log servers were upgraded to R80.
    * Scenario 3 additional symptoms  
    Show / Hide symptom  

    * Domain Management Server and/or Domain Log Server were just upgraded.
    * `"Log resolution failed. Logs might not display properly"` message when Smartlog is opened, after an upgrade.

## Cause

* Scenario 1  
  Show / Hide cause  

  * When installing a Multi-Domain server machine and performing the First Time Wizard, an IP address was configured as the Leading IP. This IP address is different from the IP address that is configured in the mds_backup file, as the Leading IP.

  * Scenario 2  
  Show / Hide cause  

  * The file $RTDIR/conf/logServerConfig.xml is missing the Loopback Port value:

    ```
    <LoopbackPort>18244</LoopbackPort>.
    ```

    <br />

    This causes the log_indexer_proxy not to know the log_indexer port in url such as: https://localhost:18244/get_docs.

  * Scenario 3  
  Show / Hide cause  

  * The CLM versions on the log server still shows the pre-upgraded version.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
