<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit Log in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32091#M1908</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can not use this command in R76SP.50&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66485_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jun 2018 11:11:47 GMT</pubDate>
    <dc:creator>Huseyin_Rencber</dc:creator>
    <dc:date>2018-06-18T11:11:47Z</dc:date>
    <item>
      <title>Audit Log</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32089#M1906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the 13500 appliance I can find user command history, some changed configurations etc in /var/log/messages. As far as I know &lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Audit Logs for Gaia Clish commands are written by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;CODE style="background-color: #ffffff; font-size: 14px;"&gt;clishd&lt;/CODE&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;CODE style="background-color: #ffffff; font-size: 14px;"&gt;xpand&lt;/CODE&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;daemons with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;CODE style="background-color: #ffffff; font-size: 14px;"&gt;local0&lt;/CODE&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;priority to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;CODE style="background-color: #ffffff; font-size: 14px;"&gt;/var/log/messages&lt;/CODE&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file.&amp;nbsp;&lt;/SPAN&gt;For instance&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66453" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66453_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 41K chassis ( R76SP.50 version )&amp;nbsp; there is&amp;nbsp;commands for audit log such as &amp;gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66455" class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66455_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66456" class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66456_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66457" class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66457_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66454" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66454_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But after running these commands I could not find&amp;nbsp;logs like "cmd by xxx start executing" in audit files and in var/log/messages. Where can I look for audit log, is there a way to find user clish history on 41K appliance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2018 19:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32089#M1906</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-17T19:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Log</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32090#M1907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try asg_auditlog command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 10:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32090#M1907</guid>
      <dc:creator>Sancar_Capi</dc:creator>
      <dc:date>2018-06-18T10:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Log</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32091#M1908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can not use this command in R76SP.50&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66485_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 11:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32091#M1908</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-18T11:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Log</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32092#M1909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In one of the latest JHFA this feature is available now for scalable plattforms. This was a neccessary feature for our deployment so we raised a RfE and luckily it found its way into the JHFA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 11:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Audit-Log/m-p/32092#M1909</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2018-08-10T11:02:25Z</dc:date>
    </item>
  </channel>
</rss>

