<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: audit log in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30458#M97809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We decided not to show rule numbers in the audit logs - by design. And I'd like to share this decision.&lt;/P&gt;&lt;P&gt;Remembering a rule number&amp;nbsp;may not be a good practice. Because at any given time, someone can place a rule above it, and then the number is changed.&lt;/P&gt;&lt;P&gt;So this is why when discussing change history, we try not to give the rule number as the "most important property" but rather name, UID, and the policies that hold this rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;If you are still interested with what was the number of the rule, you can use&amp;nbsp;this script -&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/6867-how-to-get-all-the-information-about-a-deleted-rule" target="_blank"&gt;https://community.checkpoint.com/thread/6867-how-to-get-all-the-information-about-a-deleted-rule&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2019 09:16:41 GMT</pubDate>
    <dc:creator>Tomer_Sole</dc:creator>
    <dc:date>2019-06-21T09:16:41Z</dc:date>
    <item>
      <title>audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30456#M97807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone encountered this issue before? searching through the changes in audit log seems that the number of security rule involved by the change is not reported , if you copy the entire message from the audit log you can have a rule uid but is not a very "fast way" to retrieve this information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63128_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 11:57:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30456#M97807</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-02-16T11:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30457#M97808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps not all the log fields are indexed...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to find what rules changed in a given session?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 17:28:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30457#M97808</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-16T17:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30458#M97809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We decided not to show rule numbers in the audit logs - by design. And I'd like to share this decision.&lt;/P&gt;&lt;P&gt;Remembering a rule number&amp;nbsp;may not be a good practice. Because at any given time, someone can place a rule above it, and then the number is changed.&lt;/P&gt;&lt;P&gt;So this is why when discussing change history, we try not to give the rule number as the "most important property" but rather name, UID, and the policies that hold this rule.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;If you are still interested with what was the number of the rule, you can use&amp;nbsp;this script -&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/6867-how-to-get-all-the-information-about-a-deleted-rule" target="_blank"&gt;https://community.checkpoint.com/thread/6867-how-to-get-all-the-information-about-a-deleted-rule&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30458#M97809</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2019-06-21T09:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30459#M97810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tomer for the reply , will push customer to name their rule for better understanding of the changes made to a rulebase&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 08:21:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/30459#M97810</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-02-21T08:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/60357#M97811</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/332"&gt;@Tomer_Sole&lt;/a&gt;&amp;nbsp; I can under to a degree not including the rule UID and not the number due the the possibility of the display rule number changing, make some sense. That said, i see other UID with seem to obfuscate troubleshooting or audit actions that have been performed, why for instance would this be necessary&lt;/P&gt;&lt;P&gt;ActionSettings.action: Changed from '6c488338-8eec-xxxx-xxxx-xxxxxxxxxxxx' to '6c488338-xxxx-xxxx-xxxx-xxxxxxxxxxxx'&lt;/P&gt;&lt;P&gt;Where the action has been changed from drop to accept. It doesnt make it easy to see what went on with this particular edit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 05:57:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/audit-log/m-p/60357#M97811</guid>
      <dc:creator>Richard_Carson</dc:creator>
      <dc:date>2019-08-15T05:57:59Z</dc:date>
    </item>
  </channel>
</rss>

