<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using rule_uid filter in log search in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262313#M61264</link>
    <description>&lt;P&gt;I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Viewing-Rule-Logs.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Viewing-Rule-Logs.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2025 12:18:59 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-10T12:18:59Z</dc:date>
    <item>
      <title>Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262305#M61260</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've been building a script that uses Management API to gather some information regarding logs.&lt;/P&gt;&lt;P&gt;I was trying to use the filter rule_uid, to just see logs regarding one specific rule, but no matter what uid I use, I never get results. I can just search for the UID of the rule with no key information, and it looks like only logs from that rule appear, however I would feel more confident if I could use a key:value filter to guarantee that I only get the logs I require (I attached photos of the filter results in the post).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I know about the rule:&amp;lt;number of rule&amp;gt; filter, but I have multiple policies, so multiple rules number 1, 2, 3 etc... I could match that with the origin or something like that, but my life would be a lot easier if the filter rule_uid just worked.&lt;/P&gt;&lt;P&gt;Am I using the filter correctly? Anyone else knows of a key:value filter that would give me all logs of a specific rule, and that doesn't rely on repeatable values, like rule number or rule name?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 11:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262305#M61260</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-11-10T11:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262308#M61261</link>
      <description>&lt;P&gt;Im fairly sure it only works with UID itself, not rule_uid: flag, but I could be mistaken. Let me play around with it in the lab and will update you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 11:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262308#M61261</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T11:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262310#M61263</link>
      <description>&lt;P&gt;You might be right. It is weird that we would have a rule_uid filter that doesn´t work though, even though it is hidden under the Other fields option. Perhaps a leftover from previous versions.&lt;BR /&gt;&lt;BR /&gt;Either way thank you for testing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 11:50:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262310#M61263</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-11-10T11:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262313#M61264</link>
      <description>&lt;P&gt;I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Viewing-Rule-Logs.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Viewing-Rule-Logs.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 12:18:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262313#M61264</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T12:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262342#M61266</link>
      <description>&lt;P&gt;of course mate! We all work as a team to find the solution, happy we can help.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 14:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262342#M61266</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T14:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262343#M61267</link>
      <description>&lt;P&gt;Perfect, it also works on my end.&lt;/P&gt;&lt;P&gt;The filter they show doesn't work but this hidden filter does&lt;SPAN&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 14:36:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262343#M61267</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-11-10T14:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Using rule_uid filter in log search</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262345#M61268</link>
      <description>&lt;P&gt;If you want me to test anything else in the lab, please let me know. I have really good R82 lab that manages both R82 and R81.20 clusters, as well as dedicated R82 smart event server, so its super convenient for any testing.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 14:46:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-rule-uid-filter-in-log-search/m-p/262345#M61268</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T14:46:41Z</dc:date>
    </item>
  </channel>
</rss>

