> Source: [sk176803](https://support.checkpoint.com/results/sk/sk176803)

# sk176803 - Log retention policy is not applied on Management Server / Log Server

| Property | Value |
|----------|-------|
| Solution ID | sk176803 |
| Date Created | 2021-12-09 |
| Last Modified | 2023-03-22 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- In SmartConsole, users configure a Log Server to delete logs after a specified number of days. However, the Log Server shows logs that are older than the specified number of days.

## Cause

In the screenshot below, the current design limitation is that when the yellow checkbox in **(1)** is cleared (also known as "emergency maintenance") the settings configured in **(2)** are not applied (also known as "daily log retention policy"):

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1638869682690/2021-12-07_12-10-23202112071210563.bmp)

It is uncommon for users to turn off emergency maintenance. Changes to the emergency maintenance settings do not directly affect the log retention policy.

However, if you turn off emergency maintenance, logging can stop due to lack of disk space.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20 (Titan)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 93
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 82
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 196

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

Also, this workaround is available:

1. Select **When disk space is below \[Number\] start deleting old files** .  
   If disk space is below the configured value, the oldest files are deleted first.  
   This check runs on a one-minute interval.  
   **Note** - If logs are written very quickly, this setting may cause problems.
2. Select **Run the following script before deleting old** files.
3. Enter a script to offload logs onto an external server when free space reaches the configured value.  
   **Important** - You must create this shell script.
4. Click OK.
5. Install database on all servers.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
