> Source: [sk171340](https://support.checkpoint.com/results/sk/sk171340)

# sk171340 - SmartEvent not getting logs from one Multi-Log Management after restore

| Property | Value |
|----------|-------|
| Solution ID | sk171340 |
| Date Created | 2021-01-04 |
| Last Modified | 2021-07-04 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Symptoms

- * Log Server status from SmartEvent shows "The Correlation Unit can't connect to one of its Log Servers. Please make sure connectivity between the Correlation Unit and Log Server isn't blocked. There is no need to stop the job.", after Multi-Log Management restore.

* $FWDIR/log/fwd.elg logs on log server shows fw.logtrack is missing the file that SmartEvent is requesting.

* Log switch on the log server causes the fwd process to stop working.

## Cause

The log server does not have all files requested by SmartEvent Server after restore.

fw.logtrack is missing the entry for the file requested by SmartEvent Server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
