<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: messages logs on our management server show actions from my account that I am not doing. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/200559#M33463</link>
    <description>&lt;P&gt;Running a "watch api status" for a few seconds produces this exact same set of log messages.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 21:56:54 GMT</pubDate>
    <dc:creator>Ian</dc:creator>
    <dc:date>2023-12-13T21:56:54Z</dc:date>
    <item>
      <title>messages logs on our management server show actions from my account that I am not doing.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/194116#M32488</link>
      <description>&lt;P&gt;Hello! Quite a strange one, I happened to be looking into the /var/log/messages of our management server, and I saw continuous log entries from my own user account (lets call it "Bob"), seemingly running two different commands on repeat at different hours of the day. The commands running look to be "ver" and "show web ssl-port".&lt;/P&gt;&lt;P&gt;There doesn't look to be a pattern in the interval it occurs. It might not happen for a few hours, then it'll spam over several hours. I don't have any scripts running that I am aware of. In the secure logs, there are no suspicious authentication entries from my account. So this session must have been open for a long time.&lt;/P&gt;&lt;P&gt;Has anybody seen anything like this before? All I can imagine is that an old session is stuck or something like this, and it is randomly cycling through these commands.. so strange. And it goes back as far as I can see in "messages.10" from August.&lt;/P&gt;&lt;P&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:6400 t&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6400]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6400]: cmd by bob: Start executing : show web ... (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6400]: cmd by bob: Processing : show web ssl-port (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:6400&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6400]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:6399 t&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6399]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6399]: cmd by bob: Start executing : show web ... (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6399]: cmd by bob: Processing : show web ssl-port (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:6399&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6399]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:6421 t&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6421]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6421]: cmd by bob: Start executing : ver (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6421]: cmd by bob: Processing : ver (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:6421&lt;BR /&gt;Oct 3 00:31:34 2023 MgmtServer clish[6421]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:6516 t&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer clish[6516]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer clish[6516]: cmd by bob: Start executing : show web ... (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer clish[6516]: cmd by bob: Processing : show web ssl-port (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:6516&lt;BR /&gt;Oct 3 00:31:35 2023 MgmtServer clish[6516]: User bob finished running clish -c from CLI shell&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Aug 30 15:13:05 2023 MgmtServer clish[27479]: cmd by bob: Processing : ver (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:05 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:27479&lt;BR /&gt;Aug 30 15:13:05 2023 MgmtServer clish[27479]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:27513 t&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer clish[27513]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer clish[27513]: cmd by bob: Start executing : show web ... (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer clish[27513]: cmd by bob: Processing : show web ssl-port (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:27513&lt;BR /&gt;Aug 30 15:13:06 2023 MgmtServer clish[27513]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:27540 t&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer clish[27540]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer clish[27540]: cmd by bob: Start executing : show web ... (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer clish[27540]: cmd by bob: Processing : show web ssl-port (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:27540&lt;BR /&gt;Aug 30 15:13:07 2023 MgmtServer clish[27540]: User bob finished running clish -c from CLI shell&lt;BR /&gt;Aug 30 15:13:13 2023 MgmtServer xpand[7609]: bob localhost t +volatile:clish:bob:27624 t&lt;BR /&gt;Aug 30 15:13:13 2023 MgmtServer clish[27624]: User bob running clish -c with ReadWrite permission&lt;BR /&gt;Aug 30 15:13:13 2023 MgmtServer clish[27624]: cmd by bob: Start executing : ver (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:13 2023 MgmtServer clish[27624]: cmd by bob: Processing : ver (cmd md5: fdsf3334234324esfsd)&lt;BR /&gt;Aug 30 15:13:13 2023 MgmtServer xpand[7609]: bob localhost t -volatile:clish:bob:27624&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate any thoughts!&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 09:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/194116#M32488</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-10-03T09:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: messages logs on our management server show actions from my account that I am not doing.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/194145#M32495</link>
      <description>&lt;P&gt;Recommend a TAC case to investigate this: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 14:44:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/194145#M32495</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-03T14:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: messages logs on our management server show actions from my account that I am not doing.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/200559#M33463</link>
      <description>&lt;P&gt;Running a "watch api status" for a few seconds produces this exact same set of log messages.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 21:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/messages-logs-on-our-management-server-show-actions-from-my/m-p/200559#M33463</guid>
      <dc:creator>Ian</dc:creator>
      <dc:date>2023-12-13T21:56:54Z</dc:date>
    </item>
  </channel>
</rss>

