- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
not sure if this was already on a roadmap.
Are there any plans to display hitcounters based on object rather on rules?
It is somehow difficult ecspecially when you have netsted groups and a large rulebase.
Splitting up the rules in 'individual single' hosts/service blow up the rulebase, disproportionate.
Is there any better approach?
cpview top connections sk167903 does not really help in this case.
Regards
We only track hit count on rules, not objects.
Seems like a feature that should have been added a long time ago.
I don't think you have any other way to actually approach this better at the moment other then spliting the rules,
or leveraging logs with filters (just need to be really specific).
Have you been using the Tops pane in the Logs tab (LOGS & MONITORING / LOGS & EVENTS (R82)) to do any of that type of analysis?
API options for that too (https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-logs~v2.0.1%20)
Maybe not relevant but there have been enhancements in that area recently:
From that post (see that post for screenshot and more):
"1. Top Matched Access Rules
Use cases
Why you’ll love it
Availability: R82.10, or R82 with Jumbo Take 36+."
@Don_Paterson wrote:
Have you been using the Tops pane in the Logs tab (LOGS & MONITORING / LOGS & EVENTS (R82)) to do any of that type of analysis?
hi,
no, I was not aware of that inside SmartConsole, only formerly in https://mgmt/smartview.
Yes with Tops, even with MDS R81.20, I can see top-talker. However not exactly that what I was looking for.
My goal was to find unused or shadowed objects, not rules:
Thanks a lot
Regards
You can find unused in the object explorer from the top left menu, then choose unused.
Hey Andy,
I think it is more about objects that are actually used in the rules (no unused) but the rules that those objects are in are not matched specifically for that objects.
The objects are obviously not alone in the SRC or DST cell and are in a group or along with multiple other objects.
Regards,
Don
I see what you mean! Btw, I did check in the lab in regards to tops tab in logs and monitor, but does not appear to give anything hit count related for the objects.
Yeah, its a good one.
One thing you might like to look at:
In the Logs tab (SmartLog) click the options button (top right - at the end of the query bar) --> Tools --> Query Settings
In the Query Settings window you can change the Maximum to 50.
Then OK and go back to the Tops tab and expand Top Destinations.
It's not a lot, 50, and doesn't solve the problem but can help in some cases.
Also try this: query service:https (All Time) and then look at top destinations. As an example.
Hey Don,
Yes, I did that this morning, but still does not show any hit count per object, unless Im missing something?
this is on the roadmap for Policy Insights for 2026. It's a paid feature by the way.
Wont be free?
No, licensed under the SKU -COMPLETE
So you have:
CPSM-NGSM10-COMPLETE
CPSM-NGSM10-PREMIUM
CPSM-NGSM10
complete provides the usage per object in a rule (When implemented according to roadmap)
This also required uploading rulebase and telemetry to the cloud for analysis.
/Henrik
Ah, got it, thank you!
That is an excellent idea. I will say though, for now, cpview and tops pane @Don_Paterson mentioned are your best bet. I, personally, cant think of anything else at the moment.
I also checked smart event in my lab, but dont see any option for hit count when I create custom report. O well : - (
FWIW, I also played around with mgmt_cli commands in my mgmt lab, but appears flag show-hits only works with rule command, NOT object. Maybe someone from CP can confirm this for sure, but thats what it seems like to me.
We only track hit count on rules, not objects.
I figured as well that had to be the case, though definitely good idea, but sounds like a candidate for an RFE.
hi,
Thanks,
RFE has been created and submitted.
Definitely best option for now.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 21 | |
| 10 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Thu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY