> Source: [sk118936](https://support.checkpoint.com/results/sk/sk118936)

# sk118936 - Gateway/Virtual System does not send logs to its Log Server

| Property | Value |
|----------|-------|
| Solution ID | sk118936 |
| Date Created | 2017-07-13 |
| Last Modified | 2025-04-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * SmartView Tracker / SmartLog does not show logs from a Virtual System.

* Output of the "`ls -l $FWDIR/log/fw.log`" command on the VSX Gateway in the context of the Virtual System shows that FireWall log file grows - i.e., Virtual System's logs are saved locally.

* Kernel debug ('`fw ctl debug -v <VSID> -m fw + filter log`') on the VSX Gateway contains the following lines:

  `fw_send_kmsg: log buffer for tsid 0 is full`  
  `
  FW-1: fwloghandle_send_log: fw_send_trap failed`
* Debug of FWD daemon (per [sk86321](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86321)) on the VSX Gateway contains the following lines:

  `log_add_e__logclient: writes logs to local disk because overflow`  
  `
  log_add_e: waiting for connecting callback (log_connected) to be read`
* The above symptoms also applies to non-VSX gateways

## Cause

FWD log buffer is full. Therefore, FWD daemon is not able to send logs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
