<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Find Who have created SAM rules. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156243#M26746</link>
    <description>&lt;P&gt;If the commands were set using fw sam on the CLI within the standard clish shell, you'll see evidence of this in /var/log/messages like so:&lt;/P&gt;
&lt;P class="p1 lia-indent-padding-left-30px"&gt;&lt;SPAN class="s1"&gt;Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Start executing : &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;fw sam&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; ... (cmd md5: 70c66e959afe845950934f11615fff55)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Processing : &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;fw sam&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; -D (cmd md5: 70c66e959afe845950934f11615fff55)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s3"&gt;If it was done in SmartConsole, you might find evidence in the Audit logs in SmartConsole (haven't checked).&lt;BR /&gt;If it was done via expert mode, unless you've taken steps to explicitly log commands entered there, or you did something like&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;pointed you to, that information is not logged anywhere, at least as far as I know.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Sep 2022 15:56:25 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-09-01T15:56:25Z</dc:date>
    <item>
      <title>How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156119#M26706</link>
      <description>&lt;P&gt;Basically I like to see where details on SAM rule for user/admin who created SAM rules are stored (Not the IPs which are blocked)&lt;/P&gt;&lt;P&gt;I have tried to see Audit Logs, Log, Messaged Files from GW and SMS but no luck. And SAM.DAT fire is Binary file .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 19:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156119#M26706</guid>
      <dc:creator>FirewallGyaan</dc:creator>
      <dc:date>2022-08-31T19:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156121#M26707</link>
      <description>&lt;P&gt;I think audit log should show you that if you search for time frame and rule name.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 19:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156121#M26707</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-31T19:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156122#M26708</link>
      <description>&lt;P&gt;I did tried to add multiple Selection on Audit logs as you mentioned but no details found . I just tried to reproduce issue in my lab and same no details present anywhere. Please see attachment for Selection criteria.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 19:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156122#M26708</guid>
      <dc:creator>FirewallGyaan</dc:creator>
      <dc:date>2022-08-31T19:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156123#M26709</link>
      <description>&lt;P&gt;Incase to see issue in detail Please see video :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://youtu.be/H4fzfgwFFDQ" target="_blank"&gt;https://youtu.be/H4fzfgwFFDQ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 20:06:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156123#M26709</guid>
      <dc:creator>FirewallGyaan</dc:creator>
      <dc:date>2022-08-31T20:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156157#M26720</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;any suggestions here ?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 08:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156157#M26720</guid>
      <dc:creator>FirewallGyaan</dc:creator>
      <dc:date>2022-09-01T08:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156161#M26723</link>
      <description>&lt;P&gt;According to&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112061&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk112061: How to create and view Suspicious Activity Monitoring (&lt;STRONG&gt;SAM&lt;/STRONG&gt;) &lt;STRONG&gt;Rules&lt;/STRONG&gt;&lt;/A&gt;, this is only possible if:&lt;/P&gt;
&lt;P&gt;- SAM CLI is used&lt;/P&gt;
&lt;P&gt;- fw sam is used with option&lt;/P&gt;
&lt;TABLE border="1" width="1000" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;-e &amp;lt;key=val&amp;gt;+&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Specifies rule information based on the keys and the provided values.&lt;BR /&gt;Multiple keys are separated by the plus sign (+).&lt;BR /&gt;Available keys are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;name&lt;/EM&gt; - security rule name (limited to 100 characters)&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;comment&lt;/EM&gt; - security rule comment (limited to 100 characters)&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;originator&lt;/EM&gt; - security rule originator's username (limited to 100 characters)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;so the originator is included&lt;/P&gt;
&lt;P&gt;---&amp;gt; So what you want can be achieved if SAM rules are only created by CLI scripts embedding the originator&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 09:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156161#M26723</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-01T09:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to Find Who have created SAM rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156243#M26746</link>
      <description>&lt;P&gt;If the commands were set using fw sam on the CLI within the standard clish shell, you'll see evidence of this in /var/log/messages like so:&lt;/P&gt;
&lt;P class="p1 lia-indent-padding-left-30px"&gt;&lt;SPAN class="s1"&gt;Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Start executing : &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;fw sam&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; ... (cmd md5: 70c66e959afe845950934f11615fff55)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Processing : &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;fw sam&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; -D (cmd md5: 70c66e959afe845950934f11615fff55)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s3"&gt;If it was done in SmartConsole, you might find evidence in the Audit logs in SmartConsole (haven't checked).&lt;BR /&gt;If it was done via expert mode, unless you've taken steps to explicitly log commands entered there, or you did something like&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;pointed you to, that information is not logged anywhere, at least as far as I know.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 15:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-Find-Who-have-created-SAM-rules/m-p/156243#M26746</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-01T15:56:25Z</dc:date>
    </item>
  </channel>
</rss>

