<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony Endpoint for Linux Event Log in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180719#M7017</link>
    <description>&lt;P&gt;Seen and read that file.&lt;BR /&gt;What I'm after is an equivalent of running "cpefrcli -b backup.db" on a Windows instance of Endpoint Security.&lt;BR /&gt;This command copies the Forensics database (SQLite format DB) which can then be examined for a very detailed view of everything that happened on the system.&lt;BR /&gt;&lt;BR /&gt;Such information should exist somewhere on the system, even if briefly since a large dataset gets piped to Threat Hunting.&lt;BR /&gt;I'm wondering if there's a way to capture this dataset locally just as we are able to with Windows Harmony Endpoint.&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2023 08:50:34 GMT</pubDate>
    <dc:creator>Swiftyyyy</dc:creator>
    <dc:date>2023-05-12T08:50:34Z</dc:date>
    <item>
      <title>Harmony Endpoint for Linux Event Log</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180696#M7015</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;Would you happen to know if Harmony Endpoint for Linux also stores a local database of events similar to the Windows variant.&lt;BR /&gt;I am talking about the SQLite database into which the Forensics blade deposits information about Socket operations, Running processes, File operations and more.&lt;/P&gt;&lt;P&gt;As the Linux variant of Harmony Endpoint became supported for On-Premises appliances where Threat Hunting of course isn't available, at least having this database available somewhat adds some value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 05:27:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180696#M7015</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2023-05-12T05:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint for Linux Event Log</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180716#M7016</link>
      <description>&lt;P&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk170198" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk170198: &lt;STRONG&gt;Harmony&lt;/STRONG&gt; Endpoint for &lt;STRONG&gt;Linux&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;and &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Harmony-Endpoint-for-Linux-Commands.htm?Highlight=linux" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Harmony-Endpoint-for-Linux-Commands.htm?Highlight=linux&lt;/A&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="Procedure_Heading"&gt;To show detections of &lt;STRONG&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_amal variable"&gt;Anti-Malware&lt;/SPAN&gt;&lt;/STRONG&gt;, run:&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Code" style="mc-table-style: url('../Resources/TableStyles/TP_Table_Code.css');" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL /&gt; &lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Code-Body-Body1"&gt;
&lt;TD class="TableStyle-TP_Table_Code-BodyA--Body1"&gt;
&lt;P&gt;&lt;CODE&gt;cpla am detections&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" style="margin-left: 0; margin-right: auto; mc-table-style: url('../Resources/TableStyles/TP_Table_Notes.css');" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Image" /&gt; &lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Text" /&gt; &lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyB-Column_Style_Image-Body"&gt;&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt; - To limit the number of detections displayed, use the parameter --limit &amp;lt;number_of_detections&amp;gt;. Default is 100.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class="Procedure_Heading"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="Procedure_Heading"&gt;To show the latest detections of &lt;STRONG&gt;Behavioral Guard&lt;/STRONG&gt;, run:&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Code" style="mc-table-style: url('../Resources/TableStyles/TP_Table_Code.css');" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL /&gt; &lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Code-Body-Body1"&gt;
&lt;TD class="TableStyle-TP_Table_Code-BodyA--Body1"&gt;
&lt;P&gt;&lt;CODE&gt;cpla bg detections&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" style="margin-left: 0; margin-right: auto; mc-table-style: url('../Resources/TableStyles/TP_Table_Notes.css');" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Image" /&gt; &lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Text" /&gt; &lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyB-Column_Style_Image-Body"&gt;&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt; - To limit the number of detections displayed, use the parameter --limit &amp;lt;number_of_detections&amp;gt;. Default is 100.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H2&gt;Logs&lt;/H2&gt;
&lt;P class="Procedure_Heading"&gt;To collect the logs of the product:&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Code" style="mc-table-style: url('../Resources/TableStyles/TP_Table_Code.css');" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL /&gt; &lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Code-Body-Body1"&gt;
&lt;TD class="TableStyle-TP_Table_Code-BodyA--Body1"&gt;
&lt;P&gt;&lt;CODE&gt;cpla collect-logs&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" style="margin-left: 0; margin-right: auto; mc-table-style: url('../Resources/TableStyles/TP_Table_Notes.css');" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyB-Column_Style_Image-Body"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt; - When you use this command, it prepares a Zip file which you can send to the support manually.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 12 May 2023 08:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180716#M7016</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-12T08:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint for Linux Event Log</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180719#M7017</link>
      <description>&lt;P&gt;Seen and read that file.&lt;BR /&gt;What I'm after is an equivalent of running "cpefrcli -b backup.db" on a Windows instance of Endpoint Security.&lt;BR /&gt;This command copies the Forensics database (SQLite format DB) which can then be examined for a very detailed view of everything that happened on the system.&lt;BR /&gt;&lt;BR /&gt;Such information should exist somewhere on the system, even if briefly since a large dataset gets piped to Threat Hunting.&lt;BR /&gt;I'm wondering if there's a way to capture this dataset locally just as we are able to with Windows Harmony Endpoint.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 08:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180719#M7017</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2023-05-12T08:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint for Linux Event Log</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180721#M7019</link>
      <description>&lt;P&gt;Ask TAC and post the answer here ! I can not test if the details from &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk164695&lt;/SPAN&gt;&lt;/SPAN&gt; are true for EPS Linux clients...&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 09:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180721#M7019</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-12T09:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint for Linux Event Log</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180819#M7024</link>
      <description>&lt;P&gt;Hello Swiftyyyy,&lt;/P&gt;
&lt;P&gt;Harmony EndPoint for Linux does not yet contain full Forensics DB capabilities, but it is absolutely on our roadmap.&lt;/P&gt;
&lt;P&gt;Opening an RFE for this capability can assist in prioritizing it further.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Doron Zuckerman&lt;BR /&gt;Harmony EndPoint R&amp;amp;D Group Manager&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2023 07:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-for-Linux-Event-Log/m-p/180819#M7024</guid>
      <dc:creator>Doron_Zuckerman</dc:creator>
      <dc:date>2023-05-14T07:17:20Z</dc:date>
    </item>
  </channel>
</rss>

