sk184475 - LOG_INDEXER process unexpectedly exits during a log exporting task
LOG_INDEXER process unexpectedly exits during a log exporting task
Product
Logging and Status
Version
R81.20, R82, R82.10
Last Modified
2026-04-06
Symptoms
- When exporting large log volumes (up to 1 million logs, such as 30 days of data) from the SmartView WebUI, the Logs pane may become blank or display only the ID and marker columns. SmartConsole may display error messages such as " Problems have occurred during search" or " Query resolution failed. Logs might not display properly".
- Log server sizing is correct as per sk112797.
- LOG_INDEXER core dumps appear in /var/log/dump/usermode.
- The core.properties files are correct (scenarios 7 and 9 of sk163260 do not apply).
Cause
A buffer overflow occurs while iterating through log data, this causes the LOG_INDEXER process to exit.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 6
- Jumbo Hotfix Accumulator for R82 starting from Take 73
- Jumbo Hotfix Accumulator for R81.20 starting from Take 126
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-12-26
Last Modified: 2026-04-06