sk164452 - In large Multi-Domain environments, FWM and global level log_indexer might crash in a loop

In large Multi-Domain environments, FWM and global level log_indexer might crash in a loop

Product

Multi-Domain Security Management

Version

R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2025-04-25

Symptoms

Cause

The log_indexer process queries the FWM daemon for all the objects in the sem_tables. It keeps these objects in RAM in order to quickly resolve log data.

In a Multi-Domain machine, the Global level log_indexer will load all the data from all the domains.

In large environments, the process will run out of memory because it will try to load more than ~450,000 objects.

Solution

The fix is included in these versions (requires additional configuration):

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Configuration Procedure:

  1. Connect to the command line on the Multi-Domain Server.

  2. Log in to the Expert mode.

  3. Go to the MDS context:

    mdsenv

  4. Edit the $INDEXERDIR/log_indexer_custom_settings.conf file:

    vi $INDEXERDIR/log_indexer_custom_settings.conf

  5. After this line:

    :dns_backresolving (true)

    Add this line:

    :enable_limited_resolving (true)

When the value of this parameter is set to "true", the Global level log_indexer excludes the plain host from its query. This decreases the number of objects returned from the CPMI query. 6. Save the changes and exit Vi editor. 7. Restart the Indexer service:

stopIndexer ; startIndexer

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General Status: Approved by TAC Date Created: 2020-01-13 Last Modified: 2025-04-25