> Source: [sk94288](https://support.checkpoint.com/results/sk/sk94288)

# sk94288 - $FWDIR/log/ directory on Security Management Server / Log Server contains FireWall log files named "HOSTNAME__YYYY-MM-DD_HHMMSS.log" and/or "HOSTNAME1__HOSTNAME2__YYYY-MM-DD_HHMMSS.log"

| Property | Value |
|----------|-------|
| Solution ID | sk94288 |
| Date Created | 2013-08-20 |
| Last Modified | 2018-03-12 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |
| Platform | Smart-1 |

## Symptoms

- `$FWDIR/log/` directory on Security Management Server / Log Server contains FireWall log files named "`HOSTNAME__`*YYYY-MM-DD_HHMMSS*`.log`", and/or "`HOSTNAME1__HOSTNAME2__`*YYYY-MM-DD_HHMMSS*`.log`".  

*Examples* :  

* `SecCMA03__2013-02-28_235500.log` (where *SecCMA03* is the name of the Secondary CMA)
* `SecCMA03__Fw01__2013-06-23_135606_2.log` (where *Fw01* is the name of the Security Gateway)

## Cause

These log files are FireWall log files, which have been forwarded to this Security Management Server / Log Server from another Log Server, or from Security Gateway.

The '*HOSTNAME*' part of the log file name is the hostname of the machine, which has forwarded this log file.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
