> Source: [sk179865](https://support.checkpoint.com/results/sk/sk179865)

# sk179865 - In The IPS Logs, The Fields "Sent Bytes" And "Received Bytes" Show The Value "0"

| Property | Value |
|----------|-------|
| Solution ID | sk179865 |
| Date Created | 2022-09-29 |
| Last Modified | 2022-11-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- In the Security Gateway logs generated by the "IPS" Software Blade, the fields "*sent bytes* " and "*received bytes*" show the value "0".

## Cause

By design, when only the IPS Software Blade is enabled in the security gateway object, the security gateway does not keep the byte count information. This helps improve the security gateway's performance.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk173903)

Check Point recommends to always upgrade to the most recent version ([Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435) / [VSX](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=359) / [Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184) / [Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=166) / [SmartConsole](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=191)).

*** ** * ** ***

In this specific scenario, if it is necessary to get the byte count information in IPS logs, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a hotfix for this issue.

A support engineer will make sure the hotfix is compatible with your environment before providing the hotfix.  
For faster resolution and verification, collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the management server and security gateways / cluster members involved in the case.

**Instructions:**

1. On the security gateway / cluster, follow [sk168597: How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

2. Connect to the command line on the security gateway / each cluster member.

3. Log in to expert mode.

4. Permanently configure the value of the kernel parameter "**ips_acct_enable**" to 1:

   `fw ctl set -f int ips_acct_enable 1`
5. Reboot the security gateway.

   **Important:**
   * For a cluster, the reboot of a cluster member can cause a fail-over; Start with the sandby member.

   * This kernel parameter uses the new value only after a reboot and cannot be set on-the-fly.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
