> Source: [sk181068](https://support.checkpoint.com/results/sk/sk181068)

# sk181068 - Log entries are sent to backup instead of the Log Server due to high load

| Property | Value |
|----------|-------|
| Solution ID | sk181068 |
| Date Created | 2023-06-01 |
| Last Modified | 2026-03-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Logs are missing and take time until they are forwarded and indexed.
* Logs indicate that the Security Gateway under high load cannot send logs to the Log Server:"*sys_message: "7071166 log entries were not sent to log server xx.xx.xx.xx because of high load, but were instead sent to backup*"
* Message in the *cplog_debug* file states: *"changeWritingLogStatusToLocal: this logger writing log to LOCAL - Status: Writing logs locally due to high log rate (buffer overflow)*"

## Cause

High load on the Log Server or Security Gateway causes CPU spikes and traffic bottlenecks, which trigger local logging.

## Solution

Applying the new feature of **Dynamic Log Distribution** resolves the issue. This feature allows configuring the Security Gateway to distribute logs across multiple active Log Servers, improving log?forwarding performance and providing redundancy.  

Refer to [Logging and Monitoring R81.10 Administration Guide](https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_LoggingAndMonitoring_AdminGuide/Topics-LMG/Introduction.htm) \> Getting Started \> Understanding Logging \> Dynamic Log Distribution for instructions how to enable the feature.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
