Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Oscar_Bernat
Explorer

It is possible to make searches by "lastupdatetime" field?

Jump to solution

We work in a BAS technology to test security controls continuously, missing events because of the log suppression (default config) puts us in troubles because our test outcome is filled with false negatives (all suppressed logs)

It seems that the field "lastupdatetime" is not indexed by default, so it can't be included in searches through the UI and also through the API.

Is there any option to force this field to be indexed? or how what do we have to change in the config to be able to search by the "lastupdatetime" field?

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Changing what field are indexed requires an RFE.
I highly recommend engaging your local Check Point office with your various requirements around logs.

View solution in original post

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Changing what field are indexed requires an RFE.
I highly recommend engaging your local Check Point office with your various requirements around logs.

View solution in original post

0 Kudos
Oscar_Bernat
Explorer

Thanks a lot for all your quick responses.

0 Kudos