<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management API Reference + Threat emulation global exceptions in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223581#M8667</link>
    <description>&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;Thanks for the quick reply &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The prompt gives me the upper box of the exceptions instead of the bottom box:&lt;/P&gt;&lt;P&gt;**I am attaching a screenshot of the smartconsole - As you can see the "comments" are the same between the output and the screenshot...&lt;/P&gt;&lt;P&gt;I need the Global exceptions rules themselves... not the group....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;uid: "82006125-3aca-41ea-9a92-519d6065b810"&lt;BR /&gt;name: "Global Exceptions"&lt;BR /&gt;type: "exception-group"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;name: "SMC User"&lt;BR /&gt;domain-type: "domain"&lt;BR /&gt;apply-on: "all-threat-rules"&lt;BR /&gt;comments: "Out of the box global exception group for threat prevention"&lt;BR /&gt;color: "black"&lt;BR /&gt;icon: "ThreatPrevention/Exception_Group_Objects"&lt;BR /&gt;tags: []&lt;BR /&gt;meta-info:&lt;BR /&gt;lock: "unlocked"&lt;BR /&gt;validation-state: "ok"&lt;BR /&gt;last-modify-time:&lt;BR /&gt;posix: 1513272839206&lt;BR /&gt;iso-8601: "2017-12-14T19:33+0200"&lt;BR /&gt;last-modifier: "System"&lt;BR /&gt;creation-time:&lt;BR /&gt;posix: 1513272839206&lt;BR /&gt;iso-8601: "2017-12-14T19:33+0200"&lt;BR /&gt;creator: "System"&lt;BR /&gt;read-only: true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2024 07:40:05 GMT</pubDate>
    <dc:creator>Ohad</dc:creator>
    <dc:date>2024-08-14T07:40:05Z</dc:date>
    <item>
      <title>Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223513#M8663</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying my best to work with the API document of CheckPoint:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/show-threat-rule-exception-rulebase~v1.9.1%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html?#cli/show-threat-rule-exception-rulebase~v1.9.1%20&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But as always its murky at best..&lt;/P&gt;&lt;P&gt;I have R81.10 with a custom policy and it own set of exceptions..&lt;/P&gt;&lt;P&gt;I want to "migrate" all those exceptions to the global exceptions since I am planning to move from the custom policy to the autonomous one... however its like 100 + rules...&lt;/P&gt;&lt;P&gt;As you can see in the example that they present:&lt;/P&gt;&lt;P&gt;mgmt_cli set threat-exception name "Exception Rule" layer "New Layer 1" rule-number 1 new-name "Last rule"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This example does not refer to the main global exceptions under threat preventions ==&amp;gt; Exceptions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can tell that this is not the case since when using #&lt;SPAN&gt;mgmt_cli show threat-exception it shows the exceptions for the custom policy exceptions and not the global..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas would be appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 14:41:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223513#M8663</guid>
      <dc:creator>Ohad</dc:creator>
      <dc:date>2024-08-13T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223521#M8665</link>
      <description>&lt;P&gt;Have you tried using the following command: show exception-group name "Global Exceptions"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 15:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223521#M8665</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2024-08-13T15:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223581#M8667</link>
      <description>&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;Thanks for the quick reply &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The prompt gives me the upper box of the exceptions instead of the bottom box:&lt;/P&gt;&lt;P&gt;**I am attaching a screenshot of the smartconsole - As you can see the "comments" are the same between the output and the screenshot...&lt;/P&gt;&lt;P&gt;I need the Global exceptions rules themselves... not the group....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;uid: "82006125-3aca-41ea-9a92-519d6065b810"&lt;BR /&gt;name: "Global Exceptions"&lt;BR /&gt;type: "exception-group"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;name: "SMC User"&lt;BR /&gt;domain-type: "domain"&lt;BR /&gt;apply-on: "all-threat-rules"&lt;BR /&gt;comments: "Out of the box global exception group for threat prevention"&lt;BR /&gt;color: "black"&lt;BR /&gt;icon: "ThreatPrevention/Exception_Group_Objects"&lt;BR /&gt;tags: []&lt;BR /&gt;meta-info:&lt;BR /&gt;lock: "unlocked"&lt;BR /&gt;validation-state: "ok"&lt;BR /&gt;last-modify-time:&lt;BR /&gt;posix: 1513272839206&lt;BR /&gt;iso-8601: "2017-12-14T19:33+0200"&lt;BR /&gt;last-modifier: "System"&lt;BR /&gt;creation-time:&lt;BR /&gt;posix: 1513272839206&lt;BR /&gt;iso-8601: "2017-12-14T19:33+0200"&lt;BR /&gt;creator: "System"&lt;BR /&gt;read-only: true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 07:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223581#M8667</guid>
      <dc:creator>Ohad</dc:creator>
      <dc:date>2024-08-14T07:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223600#M8670</link>
      <description>&lt;P&gt;Ah sorry, try this one: show threat-exception name "Test" exception-group-name "Global Exceptions"&lt;/P&gt;
&lt;P&gt;You can extend the output by setting the detail level to full like this:&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;show threat-exception name &lt;/SPAN&gt;&lt;SPAN&gt;"Test"&lt;/SPAN&gt;&lt;SPAN&gt; exception-group-name &lt;/SPAN&gt;&lt;SPAN&gt;"Global Exceptions"&lt;/SPAN&gt;&lt;SPAN&gt; details-level full &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Aug 2024 08:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223600#M8670</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2024-08-14T08:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223608#M8671</link>
      <description>&lt;P&gt;Cool, it shows the rule now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now for the 1 million question - How to add a rule to said group...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The syntax is:&lt;/P&gt;&lt;P&gt;mgmt_cli add threat-exception layer "New Layer 1" rule-number 1 position 1 name "Exception Rule" track "Log" protected-scope "All_Internet" protection-or-site "Adware.a" --format json&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am assuming it would be something like:&lt;/P&gt;&lt;P&gt;mgmt_cli add threat-exception layer "Global Exceptions" rule-number 12 name "Test12" source-name "ohad-pc" service-name "smtp" destination "ohad-pc" protection-or-site "Anti-Virus" action "Inactive" track "Log"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I am getting an error message:&lt;/P&gt;&lt;P&gt;code: "generic_err_invalid_parameter_name"&lt;BR /&gt;message: "Unrecognized parameter [service-name]"&lt;/P&gt;&lt;P&gt;Executed command failed. Changes are discarded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if I were to plan ahead, I think the best way to go would be to export the current 100+ rules into a csv, and use the batch flag like when using:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt_cli add host --batch hosts.csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont see in the URL any provided information in case I want to use a batch file instead of single commands...&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 09:45:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223608#M8671</guid>
      <dc:creator>Ohad</dc:creator>
      <dc:date>2024-08-14T09:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223644#M8672</link>
      <description>&lt;P&gt;It’s service, not service-name.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#cli/add-threat-exception~v1.9.1%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/#cli/add-threat-exception~v1.9.1%20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Exporting the existing rules into a CSV is probably possible with some scripting involving the jq utility.&lt;BR /&gt;For it to be importable with the batch option, you need to construct the CSV correctly.&lt;BR /&gt;Consider you are passing name/value pairs via mgmt_cli.&lt;BR /&gt;The first (header) line includes the “names” you pass (e.g. layer, rule-number…).&lt;BR /&gt;Subsequent lines have the relevant values.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 13:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/223644#M8672</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-14T13:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Management API Reference + Threat emulation global exceptions</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/224070#M8681</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39733"&gt;@Ohad&lt;/a&gt;&amp;nbsp;, try the API call below:&lt;/P&gt;
&lt;P&gt;mgmt_cli add threat-exception name "Test12" position bottom exception-group-name "Global Exceptions" source &lt;SPAN&gt;"ohad-pc"&lt;/SPAN&gt; service "smtp" destination &lt;SPAN&gt;"ohad-pc"&lt;/SPAN&gt; protection-or-site "AntiVirus" action "Inactive" track "Log"&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Management-API-Reference-Threat-emulation-global-exceptions/m-p/224070#M8681</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2024-08-20T14:00:05Z</dc:date>
    </item>
  </channel>
</rss>

