The information you are about to copy is INTERNAL!
DO NOT share it with anyone outside Check Point.
Log Exporter stops working intermittently
SmartEvent / Eventia Analyzer, SmartLog
Platform / Model
Log Exporter stops sending logs after running for several hours. A restart of the Log Exporter resolves the issue for another few hours.
In file log_indexer.elg:
LogFormatExtractor::extractFields - Failed to read log data.. Note: You will find log_indexer.elg in the following directory: $EXPORTERDIR/targets/your_exporter_target_name/log/log_indexer.elg
There is a large amount of log formats (unexpected count) which overflow one of the format related arrays with limited size. As a result, multi thread mutex is not released, and the flow is stuck.