# $FWDIR/log/fwd.elg is corrupted during log rotation

**Product**: Multi-Domain Security Management, Security Gateways, Security Management  
**Version**: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82.10  
**OS**: Gaia  
**Last Modified**: 2025-03-06

## Symptoms

- When you open the `$FWDIR/log/fwd.elg` file in the Vi editor, the characters "`^@`" appear repeatedly.

Example:

- When you open the `$FWDIR/log/fwd.elg` file in an advanced text editor like Notepad++, the beginning of the file is filled with "NULL" characters.
- The FWD daemon is **not** running in the debug mode. ( [How to debug FWD daemon](https://support.checkpoint.com/results/sk/sk86321))

For corruption in debug mode, please review [Log files can become corrupted when running debug of Check Point daemons on Gaia OS](https://support.checkpoint.com/results/sk/sk52120).

## Cause

The internal log rotation mechanism rotates this log file when its size reaches a configured threshold.

In rare cases, the log rotation mechanism rotates the log file while the Gaia OS writes the data into it.

## Solution

This problem was fixed. The fix is included starting from:

- [Check Point R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 26
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 81
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 87

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ( [Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions**:

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE

This solution has been verified for the specific scenario described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2023-03-14  
**Last Modified**: 2025-03-06
