> Source: [sk52100](https://support.checkpoint.com/results/sk/sk52100)

# sk52100 - /var/log/messages shows 'Log buffer is full'

| Property | Value |
|----------|-------|
| Solution ID | sk52100 |
| Date Created | 2010-08-07 |
| Last Modified | 2023-09-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- */var/log/messages* files show:
`FW-1: Log buffer is full`  
`FW-1: lost `*N*` log/trap messages`

## Cause

The kernel module maintains a cyclic buffer of waiting log messages.

This log buffer queue was overflown (i.e., new logs are added before all the previous ones are being read - causing in legit messages to be overwritten) resulting in the above messages.

Most probable causes can be:

* high CPU utilization
* high levels of logging
* increased traffic
* change in logging

These messages were also observed when `$FWDIR/log/fw.log` becomes very large (e.g., 750MBb or 1GB).

This can cause different issues since it can block kernel traps (sent to User Space daemons) that may be essential for the Security Gateway to work.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
