> Source: [sk182770](https://support.checkpoint.com/results/sk/sk182770)

# sk182770 - Files and directories related to Indicators of Compromise (IoC) are different across Security Gateway Modules 

| Property | Value |
|----------|-------|
| Solution ID | sk182770 |
| Date Created | 2024-10-17 |
| Last Modified | 2024-10-27 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.20, R81.20 |

## Symptoms

- The files and directories associated with Indicators of Compromise (IoC) exhibit inconsistencies across various Security Gateway Modules.

### Examples of Discrepancies:

1. The symbolic link directory at `$FWDIR/amw/ext_ioc/cur` points to different target directories (0 or 1) on different Security Gateway Modules.
2. There are variations in symbolic links and file placements within the `$FWDIR/amw/ext_ioc/cur` directory across different Security Gateway Modules.
3. The file `ioc_gen_params.C` is available on some Security Gateway Modules but is absent on others.
4. The directory structures and file modification timestamps differ between Security Gateway Modules.

## Cause

A lag occurred in policy installation synchronization. During the deployment of new policies, not all Security Gateway Modules completed the synchronization process simultaneously. The lag caused temporary inconsistencies in IoC data, symbolic links, and file placements in the `$FWDIR/amw/ext_ioc/cur symlink` directory.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
