> Source: [sk25164](https://support.checkpoint.com/results/sk/sk25164)

# sk25164 - SmartEvent Software Blade in Management High Availability environment

| Property | Value |
|----------|-------|
| Solution ID | sk25164 |
| Date Created | 2004-02-24 |
| Last Modified | 2025-04-05 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

It is recommended to deploy and use a dedicated SmartEvent Server in Management High Availability environment.

If using a dedicated SmartEvent Server is not an option, the SmartEvent blade can only be enabled on the Active Management Server in a Management High Availability environment.

<br />

### Important Notes

* Enabling the SmartEvent Software Blade on the Standby Management Server causes the Correlation Unit and SmartEvent process to fail (SmartConsole shows an error message).

* It is **not** supported to enable the SmartEvent blade in a Full High Availability Cluster.

<br />

### Possible Scenario 1

Show / Hide this section  
1. There are two Management Servers in Management High Availability.

2. The Management Server "MGMT-A" is Active and the SmartEvent Software Blade is enabled in its object in SmartConsole.

3. The Management Server "MGMT-B" is Standby and the SmartEvent Software Blade is disabled in its object in SmartConsole.

4. The administrator changes the state between the Management Servers - the Management Server "MGMT-A" is now Standby, and the Management Server "MGMT-B" is now Active.

**Outcome:**

No action is required. It is not necessary to enable the SmartEvent Software Blade on the new Active Management Server "MGMT-B" - SmartEvent continues to run on the Standby Management Server "MGMT-A" :

The SmartView component that runs on the new Active Management Server "MGMT-B" queries the SmartEvent that runs on the Standby Management Server "MGMT-A".

The SmartEvent component on the Standby Management Server "MGMT-A" continues to index logs according to the configuration.

<br />

<br />

### Possible Scenario 2

Show / Hide this section  
1. There are two Management Servers in Management High Availability.

2. The Management Server "MGMT-A" is Active and the SmartEvent Software Blade is enabled in its object in SmartConsole.

3. The Management Server "MGMT-B" is Standby and the SmartEvent Software Blade is disabled in its object in SmartConsole.

4. The Active Management Server "MGMT-A" stops working for some reason.

5. The administrator changes the state between the Management Servers - the Management Server "MGMT-B" is now Active.

**Outcome:**

To get the SmartEvent views and reports on the Management Server "MGMT-B", it is necessary to enable the SmartEvent Software Blade in the Management Server "MGMT-B" object in SmartConsole and install the database.

The SmartEvent component on the Management Server "MGMT-B" starts indexing logs that arrive at the Server "MGMT-B".

Logs on the Management Server "MGMT-A" are not indexed. Unless the administrator configured to also store the Security Gateway logs on each Management Server. In this case, it is possible to configure SmartEvent to re-index old log data.

<br />

### Possible Scenario 3

Show / Hide this section  
1. There are two Management Servers in Management High Availability.

2. The Management Server "MGMT-A" is Active and the SmartEvent Software Blade is enabled in its object in SmartConsole.

3. The Management Server "MGMT-B" is Standby and the SmartEvent Software Blade is disabled in its object in SmartConsole.

4. The administrator changes the state between the Management Servers - the Management Server "MGMT-A" is now Standby, and the Management Server "MGMT-B" is now Active.

5. The administrator enables the SmartEvent Software Blade in the Management Server "MGMT-B" object in SmartConsole and installs the database.

**Outcome:**

No action is required. The SmartEvent component runs as expected on each Management Server.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
