- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have SmartConsole R81.10 and I would need to check in the logs who moved one rule, I have its UID.
Specifically, the rule was number 200 but someone will move it and it is now number 150.45, and because it was a bad inline rule could not execute and the move was droped by cleanup. Since the rule has no name (some oversight) I can only use the rule UID.
Ask for a hint on how to find out who moved it and when.
Quickest way is to go to the Logs & Monitor tab, open a new tab, and select Audit Log. You can search the list of changes the same way you can a traffic log. For other techniques to figure out what changes were made and by whom see here: R80+ Change Control: A Visual Guide
Quickest way is to go to the Logs & Monitor tab, open a new tab, and select Audit Log. You can search the list of changes the same way you can a traffic log. For other techniques to figure out what changes were made and by whom see here: R80+ Change Control: A Visual Guide
I tried "Change Report" but according to SK166435 (https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...) "Moving a rule in the policy will not appear in the report"
I tried to look for it in Audit logs but there are a lot of changes and I would need to filter it to have results only for a specific rule UID, is there such a filter? or where can i find information about all available filters?
ok, looks like some sms error. I created a test rule, copied the UID and pasted it in Audit Logs in the serch field. It found all the changes I made.
I don't know why but for the rule I'm looking for (using its UID) the last changes it finds are those from 2 years ago. But according to Installation History, the rule was moved 14 days ago.
Does anyone have any idea why I can't see this change?
Can you send a screenshot how you did a filter search?
Its important to follow below to make sure UUID is 100% right
https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-access-rule~v1.9%20
I took some screenshots from my lab.
Andy
Using Audit Log is not a solution to my problem. I currently have an open ticket at checkpoint, after the remote session they also found that there was an error. They are currently trying to replicate the misbehavior in their lab. For some reason, only the changes made by one user 12 days ago are not shown in the adit log (at least that's the only one I know of, because there may be more).
I was hoping someone here had had a similar problem and found a solution.
You can review /var/log/audit files and see if there is anything of interest there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY