> Source: [sk129953](https://support.checkpoint.com/results/sk/sk129953)

# sk129953 - "SmartLog is not Active" errors

| Property | Value |
|----------|-------|
| Solution ID | sk129953 |
| Date Created | 2018-06-22 |
| Last Modified | 2024-09-25 |
| Technical Level | General |
| Products | SmartConsole, Multi-Domain Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |

## Solution

### "`SmartLog is not Active`" error message in SmartConsole's "Logs and Monitor" view

Show / Hide this section  
**Symptoms:**   

* When you open the **Logs and Monitor** view in SmartConsole, this message appears: `SmartLog is not Active` (Scenario 1 and 5).
* The log file `$SMARTLOGDIR/log/smartlog_server.elg` shows this error:  
  `FieldPermissions::FieldPermissions: Fatal Error: Bad fwset format in file: [conf/log_fields.C]` (Scenario 1).
* After a database import (Multi-Domain Server backup/restore, or Multi-Domain Server export/import), these logging configuration files:   
  `* smartlog_settings.txt `  
  `*log_indexer_settings.conf `  
  `* logServerConfig.xml`   
  contain the old IP address instead of the new IP address (Scenario 2).
* The log file `$SMARTLOGDIR/log/smartlog_server.elg` shows this error:  
  `CpmiConnections::Init: Server:[] name not resolved Login::Start: Authentication failure for user:[] with error:[]` (Scenario 5).
* "`SmartLog is not active`" error when you open SmartConsole \> Logs \& Monitor directly on the Log Server or Domain Log Server / Cannot see logs in SmartConsole -\> Logs \& Monitor on some Domain Log Servers after an upgrade, although SmartView Tracker shows all logs (Scenario 6).

**Causes by Scenario:**

* **Scenario 1** There `log_fields.C` file is corrupted.
* **Scenario 2**The dbsync did not update the IP of the first clean server with the IP of the new database.
* **Scenario 3**   
  `/var/log/opt/CPSmartLog-R<XX>/` is missing or does not exist.
* **Scenario 4**HTTPS Inspection intercepts the SSL negotiation between the client, where Smart Console is running, and the Management Server.
* **Scenario 5** The server name in `$SMARTLOGDIR/smartlog_settings.txt `is not valid.
* **Scenario 6**   
  Data corruption may have occurred during the upgrade process.

**Solutions by Scenario:**

**Scenario 1**Replace the file with the default file:

1. Stop Check Point services:   
   *`# cpstop`*
2. Back up the corrupted file:  
   `# mv $SMARTLOGDIR/conf/log_fields.C $SMARTLOGDIR/conf/log_fields.C.old`
3. Copy the default file:  
   `# cp $FWDIR/conf/defaultDatabase/log_fields.C $SMARTLOGDIR/conf/log_fields.C`
4. Start Check Point services:   
   *# cpstart*

**Scenario 2** Replace all old IP addresses in these files:

* `smartlog_settings.txt`
* `log_indexer_settings.conf`
* `logServerConfig.xml`

1. Stop Check Point services:  
   `# mdsstop`
2. Back up these configuration files:  
   `# cp $SMARTLOGDIR/smartlog_settings.txt /var/tmp/`  
   `# cp $RTDIR/log_indexer/conf/log_indexer_settings.conf /var/tmp/`  
   `# cp /var/log/opt/CPrt-R80/conf/logServerConfig.xml /var/tmp/`
3. Edit all the files and replace the old IP(s) with the new IP of the Multi-Domain Server and, if required, the Domain Management Server:  
   `# $RTDIR/log_indexer/./log_indexer -Autoconf 127.0.0.1:18244 1`(if the Multi-Domain Server is a Log Server too. If not, change it to the new IP)  
   `# $SMARTLOGDIR/./smartlog_server -Autoconf <new_IP>:18242 1`  
   `# vi /var/log/opt/CPrt-R80/conf/logServerConfig.xml `
4. Change the old IP address to the new one.
5. Start Check Point services:   
   `# mdsstart `

**Scenario 3**Create the directory and the default sub-directories:

1. Go to `/var/log/opt/`:  
   `# cd /var/log/opt/`
2. Create the SmartLog directory:  
   `# mkdir CPSmartLog-R<XX>`
3. Create the sub-directories for` CPSmartLog-R<XX>`:  
   `# cd /var/log/opt/CPSmartLog-R<XX>/`  
   `# mkdir data`  
   `# mkdir log`
4. Restart the `smartlog_server` process:  
   `# smartlogstop`  
   `# smartlogstart`
5. Verify that these log files are present in `/var/log/opt/CPSmartLog`-`R<XX>/log/:`
   * `smartlogRun.log`
   * `smartlog_server.elg`
   * `# ls -l /var/log/opt/CPSmartLog-R<XX>/log/`
6. Verify that the `users_settings` directory was created in `/var/log/opt/CPSmartLog-R<XX>/data/`:  
   There will be user sub-directories created in `users_settings`:  
   `# ls -l /var/log/opt/CPSmartLog-R<XX>/data/`

**Scenario 4** Configure a bypass rule for the HTTPS inspection policy for the connection from the client to the Management Server.   

**Scenario 5** The name of the server is missing or invalid:  

`(`  

` :data ("/opt/CPSmartLog-R80.20/data")`  

` :server_port ("155.61.97.5:18242")`  

` :connections (`  

` :domain (`  

` :management (`  

` ` :name (**"**155.61.97.5)  

` :is_local (true)`  

` :read_mode (CPMI)`  

` )`  

` )`  

` )`  

Because of the redundant quotation, it could not resolve the server name. This occurred because the you did the procedure in sk121376 and changed this file manually. The name of the server should be a valid IP, without quotations, and it should not be empty.  

**Scenario 6**   
If you can see the logs in SmartView Tracker, clear the `FetchedFiles` and `CpmiLocalCopy` files on the affected Domain Log Server or Domain Management Server.

1. `mdsstop_customer <Domain Management Server>`
2. `mdsenv <Domain Management Server>`
3. `cd $INDEXERDIR/data`
4. `rm -rf CpmiLocalCopy FetchedFiles`
5. `mdsstart_customer <Domain Management Server>`
6. When the Domain Management Server/Domain Log Server processes are up, connect to SmartConsole and check the logs in **Logs \& Monitor**.

**Important**: Do the above steps above on each CMA on which the issue occurs.

### "`SmartLog is not active or unreachable`" error in SmartLog R77.30

Show / Hide this section  
**Symptoms** :

* When you open SmartLog, this error message appeats:   
  "`SmartLog is not active or unreachable`"
* The Smartlog_server service is terminated.
* The output of the `# $SMARTLOGDIR/smartlog_server -d` command shows:

  ```
  PDNetworkObjectsTable::PDNetworkObjectsTable: myself sic name = cn=cp_mgmt,o=XXXXX
  
  terminate called after throwing an instance of 'boost::archive::archive_exception'
  what(): invalid signature
  Aborted (core dumped)
  ```

**Solution** :   

1. Run:  
   `# smartlogstop`
2. Move the index files (`/opt/CPSmartLog-R77/data/*`) to a temporary directory:  
   `#mkdir /var/tmp/index.bkp`  
   `# mv /opt/CPSmartLog-R77/data/* /var/tmp/index.bkp/`
3. Run:  
   `# smartlogstart`

### "`SmartLog is not active`" and "`SMARTLOG_Server process is terminated`" messages when opening the "Logs and Monitor" tab

Show / Hide this section  

**Symptoms** :  

* In a rare scenario, when the user opens the **Logs \& Monitor** tab, a message may appear stating that SmartLog is not active, or that the SMARTLOG_SERVER process is terminated.
* The `$RTDIR/conf/IpPortSml.xml file i`s missing some of the log servers' IP addresses.
* In a rare scenario on Multi-Domain Server/Multi-Domain Log Server, several Domain Indexer processes may fail, generating a core dump file and printing a "`Failed to start web server (Probably another server listens on the same port)`" message in the `$INDEXERDIR/log/log_indexer.elg` file.

**Solution** :

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 38
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 195
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 149
* [Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380) starting from Take 278

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.In addition, this workaround is available:

1. Recreate the `IpPortSml.xml` file To do so, run these commands on the Multi-Domain Sever/Multi-Domain Log Server.   
   Note: `evstop `stops indexing processes on the entire Multi-Domain Sever/Multi-Domain Log Server:  

   `# evstop`  
   `# rm -f $RTDIR/conf/IpPortSml.xml`
2. Start the indexing processes:   
   `# mdsstart -s`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
