> Source: [sk184214](https://support.checkpoint.com/results/sk/sk184214)

# sk184214 - Log Exporter fails to send large log entries via UDP when Content Awareness is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk184214 |
| Date Created | 2025-10-22 |
| Last Modified | 2025-10-27 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Log Exporter intermittently stops sending logs to external Syslog server.

* Log transmission resume only after manually restarting the `cp_log_export` service.

* No core dumps are generated during the failure.

* The issue recurs every 1--2 days, especially when Content Awareness is enabled with archive inspection and extended/accounting logging.

* Exported logs contain extremely large entries, often listing hundreds of files from scanned archives (for example, Windows updates).

## Cause

This is not a Check Point issue. It is a known limitation of the User Datagram Protocol (UDP) protocol used by the `cp_log_export` process to send logs.

When Content Awareness is enabled with archive inspection and extended/accounting logging, the log entries can become very large because they include detailed lists of files from scanned archives. These oversized log entries exceed the maximum UDP packet size, causing the Log Exporter to fail to transmit them.

As a result, a backlog builds up, and the Log Exporter becomes unresponsive until it is manually restarted.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
