- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
SMS R81.10 Take 81.
The audit log is filled with Incident Viewed entries by WEB_API.
There's no DLP or 3rd-party API connecting to the SMS, but SmartEvent is active.
The closest WEB_API information I found is sk179685 but it's not matching these events.
Here's an example of log. Is there somewhere a description of this activity?
Time: 2023-01-12T18:00:40Z
Id: 0a16fa71-c926-bc13-63c0-4ac866e50000
Sequencenum: 1
Operation: Incident Viewed
Administrator: WEB_API
Machine: 127.0.0.1
Subject: Logging
General Information: Administrator: WEB_API; Incident: time1673544661.id2<xxxx>.blade02; gateway: <name_of_gateway>
Operation Number: 58
Client IP: 127.0.0.1
Sendtotrackerasadvancedauditlog:0
Type: Audit
Application: WEB_API
Origin: <SMS_NAME>
Product Family: Network
Marker: @A@@B@1673478001@C@178
Log Server Origin: <SMS_IP>
Origin Log Server IP: <SMS_IP>
Severity: Informational
Stored: true
I presume it's related to this: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
No action needs to be taken.
The SK, which I mentioned, is not about the same message. The Incident Viewed messages keep happening in that particular installation quite frequently, I don't see it anywhere else. If it's related, the SK should be expanded to include WEB_API functions as for now the customer might be inclined to think there are issues with their systems.
Please open a TAC case and have them investigate to ensure it's the same issue.
Thats what I did, initial investigations point to DLP which is not and has never been used in that setup.
I will update this post when there are more findings.
Yeah, definitely keep us posted how this ends up and what TAC tells you.
I have the same issue and it is more that it is filling logs with info we don't want. Can we turn off logging just for the administrator WEB_API?
Not that I'm aware of.
Having said that, perhaps the TAC might be able to offer something: https://help.checkpoint.com
Do you have a Log Exporter? I did a TAC case for this at the time but I got referred to the WEB_API Log In/Log Out SK and given the workload didn't have the time to dig in but since the later SMS updates this log doesn't appear anymore where it used to.
@PhoneBoy is right. Had case like that with TAC once and thats exactly what they provided, also after consulting with R&D.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 10 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY