<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CheckPoint Gateway HitCount in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234919#M45554</link>
    <description>&lt;P&gt;&lt;STRONG&gt;This answer is provided by &lt;A href="https://www.checkpoint.com/ai/copilot/" target="_blank"&gt;Infinity AI Copilot&lt;/A&gt; and should be confirmed by reviewing official documentation in &lt;A href="https://support.checkpoint.com" target="blank"&gt;Support Center&lt;/A&gt;.&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Currently, there isn't a direct command or API to retrieve security rule hit counts directly from a local gateway. The hit counts are typically aggregated and retrieved through the Check Point Management Server. &lt;/P&gt; &lt;P&gt;However, you can use the &lt;CODE&gt;cpstat&lt;/CODE&gt; command on the Management Server to get hit counts for a specific Security Gateway and save it to a file. Here's how you can do it:&lt;/P&gt; &lt;OL&gt; &lt;LI&gt;Connect to the command line on the Management Server.&lt;/LI&gt; &lt;LI&gt;Log in to the Expert mode.&lt;/LI&gt; &lt;LI&gt;Use the following command to get the hit count for a specific Security Gateway:&lt;PRE&gt;&lt;CODE class="language-bash"&gt;cpstat -h &amp;lt;IP Address of Security Gateway Object&amp;gt; blades &amp;gt; /var/log/HitCount_for_GW.txt &lt;/CODE&gt;&lt;/PRE&gt; Replace &lt;CODE&gt;&amp;lt;IP Address of Security Gateway Object&amp;gt;&lt;/CODE&gt; with the actual IP address of your Security Gateway.&lt;/LI&gt; &lt;/OL&gt; &lt;P&gt;This method allows you to export the hit count data for a specific gateway, but it still requires access through the Management Server. If you need further assistance or have any other questions, feel free to ask!&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 14:32:49 GMT</pubDate>
    <dc:creator>CheckMatesAI</dc:creator>
    <dc:date>2024-12-06T14:32:49Z</dc:date>
    <item>
      <title>CheckPoint Gateway HitCount</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234865#M45541</link>
      <description>&lt;P&gt;I can run the API/command on the Check Point Management Server to retrieve the hit counts for security rules, but it provides the aggregate hit counts for all gateways on which security policy applied rather than specific ones.&lt;/P&gt;&lt;P&gt;Is there a command, API, or method available to collect the security rule hit counts directly from a local gateway instead of through the Management Server?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 10:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234865#M45541</guid>
      <dc:creator>Pavan9096</dc:creator>
      <dc:date>2024-12-06T10:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway HitCount</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234912#M45551</link>
      <description>&lt;P&gt;Maybe this?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html?#clish/show-access-rule~v2%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html?#clish/show-access-rule~v2%20&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 14:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234912#M45551</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T14:27:41Z</dc:date>
    </item>
    <item>
      <title>CheckPoint Gateway HitCount</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234919#M45554</link>
      <description>&lt;P&gt;&lt;STRONG&gt;This answer is provided by &lt;A href="https://www.checkpoint.com/ai/copilot/" target="_blank"&gt;Infinity AI Copilot&lt;/A&gt; and should be confirmed by reviewing official documentation in &lt;A href="https://support.checkpoint.com" target="blank"&gt;Support Center&lt;/A&gt;.&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Currently, there isn't a direct command or API to retrieve security rule hit counts directly from a local gateway. The hit counts are typically aggregated and retrieved through the Check Point Management Server. &lt;/P&gt; &lt;P&gt;However, you can use the &lt;CODE&gt;cpstat&lt;/CODE&gt; command on the Management Server to get hit counts for a specific Security Gateway and save it to a file. Here's how you can do it:&lt;/P&gt; &lt;OL&gt; &lt;LI&gt;Connect to the command line on the Management Server.&lt;/LI&gt; &lt;LI&gt;Log in to the Expert mode.&lt;/LI&gt; &lt;LI&gt;Use the following command to get the hit count for a specific Security Gateway:&lt;PRE&gt;&lt;CODE class="language-bash"&gt;cpstat -h &amp;lt;IP Address of Security Gateway Object&amp;gt; blades &amp;gt; /var/log/HitCount_for_GW.txt &lt;/CODE&gt;&lt;/PRE&gt; Replace &lt;CODE&gt;&amp;lt;IP Address of Security Gateway Object&amp;gt;&lt;/CODE&gt; with the actual IP address of your Security Gateway.&lt;/LI&gt; &lt;/OL&gt; &lt;P&gt;This method allows you to export the hit count data for a specific gateway, but it still requires access through the Management Server. If you need further assistance or have any other questions, feel free to ask!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 14:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234919#M45554</guid>
      <dc:creator>CheckMatesAI</dc:creator>
      <dc:date>2024-12-06T14:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway HitCount</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234921#M45555</link>
      <description>&lt;P&gt;To confirm the answer by CheckMatesAI, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk135212" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk135212&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 14:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234921#M45555</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-06T14:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Gateway HitCount</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234923#M45556</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if this looks right (just did it in my lab), but seems some info is missing...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-MANAGEMENT:0]# cpstat -h 172.16.10.249 blades &amp;gt; /var/log/hitcount_for_gw.txt&lt;BR /&gt;[Expert@CP-MANAGEMENT:0]# more /var/log/hitcount_for_gw.txt&lt;/P&gt;
&lt;P&gt;Packets accepted : 44090826&lt;BR /&gt;Packets dropped : 13516&lt;BR /&gt;Peak number of connections: 1019&lt;BR /&gt;Number of connections: 7&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Top Rule Hits&lt;BR /&gt;-----------------------&lt;BR /&gt;|rule index|rule count|&lt;BR /&gt;-----------------------&lt;BR /&gt;-----------------------&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-MANAGEMENT:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 14:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Gateway-HitCount/m-p/234923#M45556</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T14:39:20Z</dc:date>
    </item>
  </channel>
</rss>

