How do I run a report for Check Point NG FP3 exported log files?


This article applies to:

  • Firewall Suite 4.1a
  • Security Reporting Center 2.0x
  • Security Reporting Center 2.1

Question:

How do I run a report for Check Point NG FP3 exported log files?

Symptoms:

  • Unable to report on Check Point NG FP3 exported log files.
  • Error: WebTrends could not generate the report. Possible reasons include: 1) The log file contains no records from firewalls you are licensed for. 2) The log file contains no data. 3) The log file contains no valid log file records.
  • Error: No valid data was found within the selected log files. This error can occur if the profile has the wrong log file format or the event is reporting on the wrong report range.

Causes:

Check Point FP3 adds an extra space in the date field when the date is only a single digit. 

Procedure:

A hot fix from Check Point must be installed on the firewall.  Please contact Check Point and reference the following hot fix:

Check Point NG FP3 - Hot Fix 2

After the patch has been installed on the Check Point device, you will need to export the log files again to complete the analysis.

Notes:

For more information about this issue and the hot fix please see Check Point knowledge base article SK15980.

This issue is only experienced with FP3 exported log files.  LEA log files from FP3 do not cause the issue.

This article was previously published as:
NETIQKB20377

Last Modified 4/10/2006.
https://support.trustwave.com/kb/KnowledgebaseArticle10449.aspx