sk181454 - Search in SmartConsole 'Security Policies' view highlights only some instances of the object

Search in SmartConsole 'Security Policies' view highlights only some instances of the object

Product Multi-Domain Security Management, Security Management, SmartConsole
Version R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS Gaia
Last Modified 2025-01-20

Symptoms

For example, when searching for object name "ABC" using this search query:

ABC_myhost_1.2.3.4 OR myhost_ABC_1.2.3.4 OR myhost_1.2.3.4_ABC

Cause

More than 5,000 objects that contain the search string are defined.

The query infrastructure that fetches the objects from the Postgres database sets a limit of 5,000 to the query.

Solution

This problem was fixed. The fix is included starting from:

Check Point recommends to always upgrade to the most recent version.

Best Practices

  1. Group separate similar objects into Group objects.
  2. Decrease the number of configured rules - where possible, replace multiple specific rules with more generic rules (for example, instead of configuring several rules for specific hosts on the same subnet, configure one rule using a Network object).

Instructions to configure a greater limit

Important Note – If you increase this limit, the search action in SmartConsole can consume more CPU and memory resources on the Management Server.

  1. Connect to the command line on the Management Server.
  2. Log in to the Expert mode.
  3. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
    mdsenv <IP Address or Name of Domain Management Server>
  4. Run this command:
    $MDS_TEMPLATE/scripts/reload_env_vars.sh -e "SC_SEARCH_QUERY_LIMIT=<NEW_VALUE>"
    Example for 7000:
    $MDS_TEMPLATE/scripts/reload_env_vars.sh -e "SC_SEARCH_QUERY_LIMIT=7000"

Important Note – This change does not survive a reboot. To make this change during each boot, add the required command in the " /etc/rc.d/rc.local" script:

  1. Back up the current script:
    cp -v /etc/rc.d/rc.local{,_BKP}
  2. Edit the current script:
    vi /etc/rc.d/rc.local
  3. Add these lines at the bottom of the script:
    Note – Enter your required value. After the last line, you must press the Enter key to create a new line.
    # Changes based on sk181454
    $MDS_TEMPLATE/scripts/reload_env_vars.sh -e "SC_SEARCH_QUERY_LIMIT=<NEW_VALUE>"
  4. Save the changes in the file and exit Vi editor.

Instructions to restore the default limit of 5000

  1. Connect to the command line on the Management Server.
  2. Log in to the Expert mode.
  3. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
    mdsenv <IP Address or Name of Domain Management Server>
  4. Run this command:
    $MDS_TEMPLATE/scripts/reload_env_vars.sh -e "SC_SEARCH_QUERY_LIMIT=5000"

Important Note – If you added the required command in the " /etc/rc.d/rc.local" script, then edit the script file and comment out the command - add the # character in the beginning of the command (#$MDS_TEMPLATE/scripts/reload_env_vars.sh -e ...).

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.