<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Account creation for file deletion in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257261#M50416</link>
    <description>&lt;P&gt;Second that&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":up_arrow:"&gt;⬆️&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Sep 2025 08:56:27 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2025-09-15T08:56:27Z</dc:date>
    <item>
      <title>User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257258#M50414</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to create an user account who will only have read/write/deletion access to&amp;nbsp;/var/log/opt/ this directory and it's associated files, directories via SSH/WINSCP. This is for manage space alerts in firewalls. However, I am unable to give correct permission thus user cannot go beyond past&amp;nbsp;/var/log/opt/ location. Hence reaching out here if anyone can help on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 07:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257258#M50414</guid>
      <dc:creator>ArijitNaha</dc:creator>
      <dc:date>2025-09-15T07:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257260#M50415</link>
      <description>&lt;P&gt;Such file system access restrictions are not supported as far as I know.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 08:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257260#M50415</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-15T08:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257261#M50416</link>
      <description>&lt;P&gt;Second that&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":up_arrow:"&gt;⬆️&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 08:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257261#M50416</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-15T08:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257275#M50418</link>
      <description>&lt;P&gt;So, how do i approach this? I wanted to give an user to winscp access to firewall to delete old log files when any space alert issue comes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257275#M50418</guid>
      <dc:creator>ArijitNaha</dc:creator>
      <dc:date>2025-09-15T10:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257277#M50419</link>
      <description>&lt;P&gt;In other words, you want a non-admin user with the ability to delete files? This will not work. Why not use one of the OS level admin accounts?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 11:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257277#M50419</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-15T11:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257315#M50426</link>
      <description>&lt;P&gt;Or a cronjob.&lt;/P&gt;
&lt;P&gt;You can also set a management server to delete old logs when lv_log has under X gigabytes of free space.&lt;/P&gt;
&lt;P&gt;Strictly, it should be&amp;nbsp;&lt;STRONG&gt;possible&lt;/STRONG&gt; to grant a specific user RWX access to everything under a directory using extended filesystem ACLs. New files would be created with the default permissions from the umask, though, so the user wouldn't be able to remove most logs, so a cronjob or similar would still be needed to apply the ACL. May as well have the cronjob handle the cleanup directly.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 21:01:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257315#M50426</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-09-15T21:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257433#M50450</link>
      <description>&lt;P&gt;is there any article or document that I can refer to set this up?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 05:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257433#M50450</guid>
      <dc:creator>ArijitNaha</dc:creator>
      <dc:date>2025-09-17T05:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257448#M50452</link>
      <description>&lt;P&gt;Extended ACLs are a standard Linux thing (getfacl / setfacl).&lt;BR /&gt;However, we do not include these binaries in Gaia OS.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 11:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257448#M50452</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-17T11:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257487#M50456</link>
      <description>&lt;P&gt;I could have sworn I was just working with these on a Gaia system, but sure enough, they're not present. Scratch that idea!&lt;/P&gt;
&lt;P&gt;That leaves the log cleanup options configured in SmartConsole (cleans up firewall traffic logs, but not stuff like /var/log/messages), or a cronjob.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 14:02:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257487#M50456</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-09-17T14:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257556#M50463</link>
      <description>&lt;P&gt;How to setup in Smart console to cleanup logs at /var/log/opt/CPsuite-&amp;lt;RX.x&amp;gt;/fw1/log? Which usually has that traffic logs. Any article or document you have? Or how to setup cronjob for this as you mentioned earlier?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 04:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257556#M50463</guid>
      <dc:creator>ArijitNaha</dc:creator>
      <dc:date>2025-09-18T04:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: User Account creation for file deletion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257630#M50474</link>
      <description>&lt;P&gt;Use SmartConsole to connect to your management. Open the object for the server you want to adjust. Go to Logs &amp;gt; Storage. Set the "When disk space is below _____, start deleting old files." option. When you're done configuring it, Menu button &amp;gt; Install database... and install it on at least the one you modified.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:01:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/User-Account-creation-for-file-deletion/m-p/257630#M50474</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-09-18T15:01:19Z</dc:date>
    </item>
  </channel>
</rss>

