> Source: [sk165293](https://support.checkpoint.com/results/sk/sk165293)

# sk165293 - Logs are not seen in the secondary MDS SmartConsole but are seen on the primary MDS and MLM

| Property | Value |
|----------|-------|
| Solution ID | sk165293 |
| Date Created | 2020-03-13 |
| Last Modified | 2021-12-28 |
| Technical Level | Advanced |
| Products | Multi-Domain Security Management Server, Logging & Status |
| Versions | R82.10, R82.10, R81.20, R82, R82.20, R82.20, R81.20, R82 |
| OS | Gaia |
| Platform | Smart-1, Open Server |

## Symptoms

- * Logs are not seen in the secondary MDS SmartConsole but are seen on the primary MDS and MLM. The log servers cannot be seen in the log servers section of SmartConsole.   

* From the $FWDIR/log/dbsync.elg, the logs are seen:   

  `
  DATE TIME,PID INFO db_sync.server.DBSyncData [dbsyncTaskExecutor-1]: CA IP doesn't answer, trying to connect to another IP`  
  `
  DATE TIME,PID INFO INFO db_sync.server.DBSyncData [dbsyncTaskExecutor-1]: Candidates for connection:`  
  `
  DATE TIME,PID ERROR db_sync.server.DBSyncData [dbsyncTaskExecutor-1]: Failed to connect to all machines`  
  `
  DATE TIME,PID WARN db_sync.server.CpmSession [dbsyncTaskExecutor-1]: Login failure to a0eebc99-afed-4ef8-bb6d-fedfedfedfed on <IP>. message: Marshalling Error: connect timed out`  
  `
  DATE TIME,PID WARN db_sync.server.CpmSession [dbsyncTaskExecutor-1]: Login failure to a0eebc99-afed-4ef8-bb6d-fedfedfedfed on <IP>. message: Marshalling Error: connect timed out
  `  

* The IP field above in the dbsync.elg denotes the primary MDS IP address, and this IP address does not belong to the primary MDS in the current configuration.
* "Log indexing configuration changed. smartconsole restart is required" is seen on the "Logging \& Monitor" tab

## Cause

This is due to the primary Multi-Domain Server (MDS) changing to the new IP address and the ICA IP address of the secondary MDS was not changed in the registry.  
The secondary MDS is trying to connect to the old IP address of the primary MDS when contacting the Internal Certificate Authority (ICA), but the old IP address cannot be reached.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
