> Source: [sk98126](https://support.checkpoint.com/results/sk/sk98126)

# sk98126 - Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server

| Property | Value |
|----------|-------|
| Solution ID | sk98126 |
| Date Created | 2014-01-13 |
| Last Modified | 2024-11-26 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R82, R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

1. Make sure that the Security Management and Log Server have sufficient disk space.
2. In Security Management Server / Log Server "General Properties", make sure to select the "*Logging \& Status* " checkbox:  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-11710020618.png)

3.

   ### For R80.?:

   Open Security Gateway Properties -\> go to **Logs** -\> select the "***Send gateway logs and alerts to server (\<Management server name\>)*** " checkbox:  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-21710020640.png)

   In Security Gateway Properties, go to ***Logs* -\> *Local Storage*** and set the alert for when disk space is below the threshold (default value is 20 Mbytes):  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-31710020643.png)

   **Note** that delete threshold cannot be more than 25% of the disk. Automatically delete logs if less then 12GB are available. It is recommended to delete the old files when disk space is below 15-20%.

   **For Security Management Server:**

   In Security Management Server Properties, go to ***Logs*** . Here, you can enable ***Log Indexing*** and see all the Security Gateways that send their logs to this Security Management Server:  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-41710020647.png)

   <br />

   Go to ***Logs* -\> *Storage***.

   This is where we configure the Security Management Server to switch the active log file.

   **Note**: In the Security Management Server Properties, make sure to have it set for log switch if the Management Server is the Log server.

   Select the box "***When disk space is below ... MBytes, issue alert*** ":  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-51710020651.png)

   <br />

   In Security Management Server Properties, go to ***Logs* -\> *Additional Logging***.

   Select the box "***Create a new log file when the current file size is larger than*** " (default is 1000 MBytes). It can be scheduled for any desired time. It is best to perform the switch on a daily basis.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-61710020653.png)  

   <br />

   If there is another Log Server and you want the Security Management Server to forward the logs to it, then select the "***Forward log files to Log Server*** " checkbox and then select the relevant Log Server:  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-71710020655.png)  

4.

   ### Prior to R80.x:

   Show / Hide this Section  

   Open Security Gateway Properties -\> go to Logs -\> select the Security Management Server / Log Server, to which the logs should be sent.

   **Note:** "*Use Local definitions for Masters* " option is not present. Refer to [sk73820](http://supportcontent.checkpoint.com/solutions?id=sk73820).
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/7.png)

   In Security Gateway Properties, go to *Logs* -\> *Local Storage* - set the alert for when disk space is below the threshold (default value is 20 Mbytes).
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/8.png)

   **For Security Management Server:**

   In Security Management Server Properties, go to *Logs*.

   Here, you can enable *SmartLog* and see all the Security Gateways that send their logs to this Security Management Server.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/9.png)

   Go to ***Logs* -\> *Storage*.**

   This is where we configure the Security Management Server to switch the active log file.

   Note: In the Security Management Server Properties, make sure to have it set for log switch if the Management Server is the Log server.

   Select the box "*Create a new log file when the current file size is larger than*" (default is 1000 MBytes). It can be scheduled for any desired time. It is best to perform the switch on a daily basis.

   Select the box "*When disk space is below ... MBytes, issue alert*".
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/10.png)

   <br />

   In Security Management Server Properties, go to *Logs* -\> *Additional Logging*.

   If there is another Log Server and you want the Security Management Server to forward the logs to it, then check the box "*Forward log files to Log Server*" and select the relevant Log Server.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/11.png)  

5.

   ### For versions below R75.40

   Show / Hide this Section  
   **For Security Gateway** to log to the Security Management Server or to a Log server, in the SmartDashboard, open Security Gateway Properties - go to *Logs and Masters* -\> *Masters* and select "*Define Masters*".

   OR select "*Use Local definitions for Masters* " and manually edit the *$FWDIR/conf/masters* file on Security Gateway.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/2.png)

   <br />

   In Security Gateway Properties, go to *Logs and Masters* -\> *Log Servers* - select your Security Management Server / Log Server.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/3.png)

   **For Security Management server:**

   In the Security Management Server "General Properties", make sure to have it set for log switch if the Management Server is the Log server.   
   Select the box "*Log switch when file size is*" (the default value is 500 MBytes). It can be scheduled for any time and the best is to do the switch on a daily basis.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/4.png)

   <br />

   Make sure to check the box "*Alert when free disk space is below*" (default is 20 MBytes).
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/5.png)

   <br />

   If there is another Log Server, and you want the Security Management Server to forward the logs to it, then check the box "*Forward log files to Log Server*" and select the relevant Log Server.
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/6.png)

   <br />

6. In the SmartConsole/SmartDashboard, go to *Policy* menu -\> click on *Install Database...* -\> select the Security Management Server / Log Server, to which the Security Gateway(s) will be sending logs:  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98126/sk98126-install-db1710020628.png)  

7. Install the Policy on the involved Security Gateway(s).   

8. **Check the logs in Logs \& Monitor View / SmartView Tracker.**   
   Sometimes we see the logs immediately and other times it may take more or less 5 minutes.

**Recommendations:**

* Enable Log forwarding once a day on all gateways. That way if local logging happens, it does not stick on the gateway forever.
* Enable delete and stop logging threshold on gateways as well. This way they can never run full because of local logging.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
