- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi Checkmates
Is there a way to view audit logs for logs/log files that were deleted?
Hi Andy
You're correct, I did reach out to TAC and their feedback is that the isn't a way.
hi,
IMHO no, that's the reason why we run a script/cronjob to copy audit logs to an external server.
In addition, having audit log files on a different server may help you to correlate the correct time.
SmartConsole shows audit logs with the time/timezone settings of your client PC and not of your CheckPoint MGMT server.
Regards
Thanks for the answer
See if any of below files may help.
Andy
[Expert@cpazurecluster1:0]# cd /var/log/audit/
[Expert@cpazurecluster1:0]# ls
audit.log audit.log.1 audit.log.2 audit.log.3
[Expert@cpazurecluster1:0]#
This is mostly what Im finding in my lab...
Andy
type=USER_AUTH msg=audit(1709200428.987:482949): pid=29059 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=144.217.84.62 addr=144.217.8
4.62 terminal=ssh res=failed'
type=USER_AUTH msg=audit(1709200434.568:482950): pid=29081 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=144.217.84.62 addr=144.217.8
4.62 terminal=ssh res=failed'
type=USER_AUTH msg=audit(1709200439.315:482951): pid=29111 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=218.92.0.92 addr=218.92.0.92
terminal=ssh res=failed'
[Expert@cpazurecluster1:0]# grep -i delete audit.log
[Expert@cpazurecluster1:0]# grep -i DELETE audit.log
[Expert@cpazurecluster1:0]#
Thanks Legend, I also did test the same but not finding specific traces pointing to the deleted log files.
Maybe open TAC case to confirm, but does not look like there might be a log about it : - (
Andy
Hi Andy
You're correct, I did reach out to TAC and their feedback is that the isn't a way.
K, so thats the answer then, if they confirmed already.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY