sk184144 - "api stats -calc_avg_duration" command fails with IndexError on Security Management Server
"api stats -calc_avg_duration" command fails with IndexError on Security Management Server
Product: Security Management
Version: R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-07-23
Symptoms
- Running the "
api stats" command with the "-calc_avg_duration" flag on the Security Management server fails with error:
IndexError: list index out of range
```
- The error occurs specifically when requesting statistics in text format, for example:
api stats -from_date ... -to_date ... -calc_avg_duration -f text
```
- Other subcommands of the "
api stats" command work as expected. - Replacing script files or removing the $FWDIR/log/api.csv file does not resolve the issue.
Cause
An issue with the Security Management Server API statistics parser handling certain User-Agent strings (e.g., Apache-HttpClient/4.5.13 (Java/1.8.0_372)).
This results in malformed entries in the $FWDIR/log/api.csv and its rotated files, where the expected number of columns is not met. When the "-calc_avg_duration" flag is used, the script attempts to access a non-existent list index, causing an IndexError.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Workaround
Remove Malformed Entries:
Note: Editing these files may impact system behavior. Always back up before making changes.
- Edit the file: $FWDIR/log/api.csv.
- Remove all lines with malformed User-Agent strings (e.g., missing closing quotes or brackets).
- Repeat this step for all rotated files: $FWDIR/log/api.csv.1, $FWDIR/log/api.csv.2, etc.
- Restart the API service with the command "
api restart" to apply the changes.
Note: Editing these files may impact system behavior. Back up before making changes.
Verification
- After applying the workaround or hotfix, run this command to make sure that the error no longer occurs:
api stats -from_date ... -to_date ... -calc_avg_duration -f text
```
2. Confirm that the command completes successfully and returns the expected statistics.
#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.