- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Hi all,
Is it possible to set the Track option for every new rule to 'Log' instead of 'None'?
We have a customer that would like to have this option because he logs every rule.
Regards,
Martijn.
Hi,
It is not up to me to decide for the customer it is not a big deal changing the Track option.
The security policy (written and technical) is very strict for this customer. Every action on the network and systems must be logged. So to make is fool-proof, it would be nice if the default Track action was set to 'Log'.
I will tell the customer API is a way to do it, but from SmartConsole it is not yet an option.
Martijn.
It is. Just enable it within Reporting Tools of your Global Properties.
Hi,
I have tried this, but I cannot select my log server (which is the SmartCenter).
Only unused log servers are available. Not sure what that means.
I am missing something?
Regards,
Martijn
You need another logserver then your actual one. If you look at Dannie’s screenshot you‘ll see the small enhancement.
“you have to choose another logserver then the actual one“. Meaning you need more then one logserver to get this working.
if you have only the one on your smartcenter you need a second one.
There is a dirty trick that may make this work.
Create a dummy log server object with the IP of the SmartCenter.
Totaly untested ....... but worth a shot.
Did try this, but doe not work.
In my SmartCenter I get the log "Stopped Logging" one I ad a new object with the same IP as the SmartCenter an push a policy.
It is a very big deal if you have day where are too many changes on firewall. Default logging behavior should be optional as is setting the default source/destination behavior. With API this easy, but not all companyes working with API.
We had a customer with similar requirements and some more pre defined values.
we created some rules with pre filled settings, like log, install target, description and part of the name. This rule is disabled and placed as first rule in different sections of the rulebase.
Now you can copy and paste this rule and start a new rule with predefined values. It‘s simple, not the best solution but very helpful.
Interresting workaround.
Another dirty workaround:
Check via API all rules which doesnt have logging set, change it and push the firewall.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 56 | |
| 44 | |
| 16 | |
| 14 | |
| 14 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 8 |
Thu 12 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 3: AI-Generated Malware - From Experimentation to Operational RealityFri 13 Feb 2026 @ 10:00 AM (CET)
CheckMates Live Netherlands - Sessie 43: Terugblik op de Check Point Sales Kick Off 2026Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesThu 12 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 3: AI-Generated Malware - From Experimentation to Operational RealityFri 13 Feb 2026 @ 10:00 AM (CET)
CheckMates Live Netherlands - Sessie 43: Terugblik op de Check Point Sales Kick Off 2026Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY