EXCELLENT @Nitzan_Massad
From my lab.
Andy
[Expert@CP-management:0]# mgmt_cli show logs new-query.time-frame "today" new-query.max-logs-per-request "2" new-query.type "audit" --format json
Username: admin
Password:
{
"logs" : [ {
"severity" : "Informational",
"product_family" : "Network",
"product" : "WEB_API",
"sequencenum" : "1",
"subject" : "Administrator Login",
"sendtotrackerasadvancedauditlog" : "0",
"type" : "Audit",
"orig_log_server_attr" : [ {
"isCHKPObject" : "true",
"uuid" : "40bbf9f7-8ab5-dd4e-a387-8b4f8fdd9f0e",
"resolved" : "CP-management"
} ],
"administrator" : "admin",
"orig_log_server" : "172.16.10.252",
"additional_info" : "Authentication method: Unix Password",
"orig" : "CP-management",
"machine" : "localhost",
"marker" : "@A@@B@1715832000@C@1009",
"orig_log_server_ip" : "172.16.10.252",
"stored" : "true",
"calc_desc" : "admin logged ln to WEB_API",
"client_ip" : "127.0.0.1",
"time" : "2024-05-16T12:16:24Z",
"id" : "ac100afc-a019-ad0d-6645-f91802610000",
"operation_number" : "10",
"operation" : "Log In"
}, {
"severity" : "Informational",
"product_family" : "Network",
"product" : "Expert Shell",
"sequencenum" : "1",
"subject" : "Administrator Expert Shell login",
"sendtotrackerasadvancedauditlog" : "0",
"device_type" : "MGMT",
"type" : "Audit",
"orig_log_server_attr" : [ {
"isCHKPObject" : "true",
"uuid" : "40bbf9f7-8ab5-dd4e-a387-8b4f8fdd9f0e",
"resolved" : "CP-management"
} ],
"administrator" : "admin",
"device_name" : "CP-management",
"orig_log_server" : "172.16.10.252",
"additional_info" : "SSH connection by admin user to Expert Shell",
"orig" : "CP-management",
"marker" : "@A@@B@1715832000@C@1008",
"orig_log_server_ip" : "172.16.10.252",
"stored" : "true",
"calc_desc" : "admin logged ln to Expert Shell",
"client_ip" : "172.16.10.1",
"time" : "2024-05-16T12:16:08Z",
"id" : "ac100afc-a019-ad0d-6645-f90802610000",
"operation" : "Log In"
} ],
"logs-count" : 2,
"query-id" : "admin_65e16d5b-6b3a-40ce-a7ef-e1f61446350f"
}
[Expert@CP-management:0]#