sk113241 - How to configure Gaia OS to rotate a custom log file

How to configure Gaia OS to rotate a custom log file

Product: Multi-Domain Security Management, Security Gateways, Security Management
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82.10
OS: Gaia
Last Modified: 2026-07-23

Solution

You can configure Gaia OS to rotate a custom log file, like it does with the /var/log/messages file.

Configuration Procedure:

  1. Connect to the command line on the Gaia OS.

  2. Log in to the Expert mode.

  3. Back up the current file:

    cp -v /etc/cpshell/log_rotation.conf{,_BKP}

  4. Edit the current file:

    vi /etc/cpshell/log_rotation.conf

  5. At the end of the file, add a new line:

    /<Full_Path>/<Name_of_Log_File> <File_Size_in_Bytes> <Number_of_Rotated_Files_to_Keep>

    • For example:

      /var/log/test.log 65536 20

    • You must use Spaces, and not Tabulations.

  6. Save the changes in the file and exit Vi editor.

  7. Make sure your custom log file has the "write" permission:

    chmod -v u+w,g+w /<Full_Path>/<Name_of_Log_File>

  8. Make sure Gaia OS can rotate your custom log file:

    log_start list

This output must show your custom log file.

Troubleshooting:

  1. If Gaia OS does not rotate your custom log, examine the /var/log/messages file - search for lines from the "cp_log_switch" process.

    Example from the /var/log/messages file about a bad syntax in the /etc/cpshell/log_rotation.conf file:

    Sep 5 10:54:13 2016 Host cp_log_switch[1839]: Malformed configuration file line (47)

  2. Custom log rotation configured using Gaia OS does not apply to SAML-related log files or to UserCheck Portal log files, so these logs are not rotated automatically.

    This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Important Notes:

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version, and Symptoms. It may not work in other scenarios.