- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Checkmates
Is there a way to view audit logs for logs/log files that were deleted?
Hi Andy
You're correct, I did reach out to TAC and their feedback is that the isn't a way.
hi,
IMHO no, that's the reason why we run a script/cronjob to copy audit logs to an external server.
In addition, having audit log files on a different server may help you to correlate the correct time.
SmartConsole shows audit logs with the time/timezone settings of your client PC and not of your CheckPoint MGMT server.
Regards
Thanks for the answer
See if any of below files may help.
Andy
[Expert@cpazurecluster1:0]# cd /var/log/audit/
[Expert@cpazurecluster1:0]# ls
audit.log audit.log.1 audit.log.2 audit.log.3
[Expert@cpazurecluster1:0]#
This is mostly what Im finding in my lab...
Andy
type=USER_AUTH msg=audit(1709200428.987:482949): pid=29059 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=144.217.84.62 addr=144.217.8
4.62 terminal=ssh res=failed'
type=USER_AUTH msg=audit(1709200434.568:482950): pid=29081 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=144.217.84.62 addr=144.217.8
4.62 terminal=ssh res=failed'
type=USER_AUTH msg=audit(1709200439.315:482951): pid=29111 uid=0 auid=42
94967295 ses=4294967295 subj=kernel msg='op=PAM:authentication grantors=
? acct="root" exe="/usr/sbin/sshd" hostname=218.92.0.92 addr=218.92.0.92
terminal=ssh res=failed'
[Expert@cpazurecluster1:0]# grep -i delete audit.log
[Expert@cpazurecluster1:0]# grep -i DELETE audit.log
[Expert@cpazurecluster1:0]#
Thanks Legend, I also did test the same but not finding specific traces pointing to the deleted log files.
Maybe open TAC case to confirm, but does not look like there might be a log about it : - (
Andy
Hi Andy
You're correct, I did reach out to TAC and their feedback is that the isn't a way.
K, so thats the answer then, if they confirmed already.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 8 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY