- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hi,
I am trying to create an user account who will only have read/write/deletion access to /var/log/opt/ this directory and it's associated files, directories via SSH/WINSCP. This is for manage space alerts in firewalls. However, I am unable to give correct permission thus user cannot go beyond past /var/log/opt/ location. Hence reaching out here if anyone can help on this.
Thanks!
Such file system access restrictions are not supported as far as I know.
Such file system access restrictions are not supported as far as I know.
Second that ⬆️
So, how do i approach this? I wanted to give an user to winscp access to firewall to delete old log files when any space alert issue comes.
In other words, you want a non-admin user with the ability to delete files? This will not work. Why not use one of the OS level admin accounts?
Or a cronjob.
You can also set a management server to delete old logs when lv_log has under X gigabytes of free space.
Strictly, it should be possible to grant a specific user RWX access to everything under a directory using extended filesystem ACLs. New files would be created with the default permissions from the umask, though, so the user wouldn't be able to remove most logs, so a cronjob or similar would still be needed to apply the ACL. May as well have the cronjob handle the cleanup directly.
is there any article or document that I can refer to set this up?
Extended ACLs are a standard Linux thing (getfacl / setfacl).
However, we do not include these binaries in Gaia OS.
I could have sworn I was just working with these on a Gaia system, but sure enough, they're not present. Scratch that idea!
That leaves the log cleanup options configured in SmartConsole (cleans up firewall traffic logs, but not stuff like /var/log/messages), or a cronjob.
How to setup in Smart console to cleanup logs at /var/log/opt/CPsuite-<RX.x>/fw1/log? Which usually has that traffic logs. Any article or document you have? Or how to setup cronjob for this as you mentioned earlier?
Use SmartConsole to connect to your management. Open the object for the server you want to adjust. Go to Logs > Storage. Set the "When disk space is below _____, start deleting old files." option. When you're done configuring it, Menu button > Install database... and install it on at least the one you modified.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 10 | |
| 9 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Tue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERThu 08 Oct 2026 @ 11:00 AM (EDT)
Under the Hood: Check Point SASE | Zero Trust Network Access, Step by StepFri 09 Oct 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 49: Maak kennis met Check Point R82.20Tue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERThu 08 Oct 2026 @ 11:00 AM (EDT)
Under the Hood: Check Point SASE | Zero Trust Network Access, Step by StepFri 09 Oct 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 49: Maak kennis met Check Point R82.20About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY