certego / fw1-loggrabber

FW1-Loggrabber is a command-line tool to grab logfiles from remote Checkpoint devices using OPSEC LEA (Log Export API)
GNU General Public License v2.0
52 stars 35 forks source link

Reconnecting to the log server #18

Open dav3860 opened 8 years ago

dav3860 commented 8 years ago

Hi,

Thank you for your great additions to the original fw1-loggrabber. I encounter an issue with fw1-loggrabber 2.1 in online mode and an R77.30 management/log server. If the log server is rebooted, fw1-loggrabber is not able to get logs when the server comes back up (even after a long time). If we restart fw1-loggrabber, it works again. Do you have a similar behavior ? How could we fix this ? Here are the debug logs when the issue occurs :

DEBUG: function submit_screen
DEBUG: Submit message to screen.
time=2016-09-14 13:22:37|action=drop|orig=X.X.X.X|i/f_dir=inbound|i/f_name=Mgmt|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|product=VPN-1 & FireWall-1|rule=336|rule_uid={EFE5309F-5070-489E-8339-FF224B3ED94F}|src=X.X.X.X|s_port=65258|dst=X.X.X.X|service=53|proto=udp|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={71D8E7A5-3D2E-4194-A0B4-A2B874FFCB09};mgmt=XXX;date=1473846830;policy_name=Standard]|origin_sic_name=CN=XXX.XXX.XXX,O=XXX.XXX.XXX.xd4pc5
DEBUG: function submit_screen
DEBUG: Submit message to screen.
time=2016-09-14 13:22:37|action=drop|orig=X.X.X.X|i/f_dir=inbound|i/f_name=Mgmt|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|product=VPN-1 & FireWall-1|rule=336|rule_uid={EFE5309F-5070-489E-8339-FF224B3ED94F}|src=X.X.X.X|s_port=65092|dst=X.X.X.X|service=53|proto=udp|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={71D8E7A5-3D2E-4194-A0B4-A2B874FFCB09};mgmt=XXX;date=1473846830;policy_name=Standard]|origin_sic_name=CN=XXX.XXX.XXX,O=CXXX.XXX.XXX.xd4pc5
[ 29036 4151355104]@XXX[14 Sep 13:24:17] fwasync_mux_timeout: 14: timed out after 100000 miliseconds
[ 29036 4151355104]@XXX[14 Sep 13:24:17] fwasync_mux_timeout: 14: inbuf: 0/12 outbuf: 0/0 state: 96ec80 1
[ 29036 4151355104]@XXX[14 Sep 13:24:17] fwasync_mux_timeout: 14: calling handler 96dbc0
[ 29036 4151355104]@XXX[14 Sep 13:24:17] resched timeout to conn_id=14, conn=87dd308, comm=87bd560, due to 1 active sessions
[ 29036 4151355104]@XXX[14 Sep 13:25:57] fwasync_mux_timeout: 14: timed out after 100000 miliseconds
[ 29036 4151355104]@XXX[14 Sep 13:25:57] fwasync_mux_timeout: 14: inbuf: 0/12 outbuf: 0/0 state: 96ec80 1
[ 29036 4151355104]@XXX[14 Sep 13:25:57] fwasync_mux_timeout: 14: calling handler 96dbc0
[ 29036 4151355104]@XXX[14 Sep 13:25:57] resched timeout to conn_id=14, conn=87dd308, comm=87bd560, due to 1 active sessions
and so on...