- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
We have a Checkpoint 5100 Firewall cluster on premise. We have a few hundred users connecting through Endpoint Security to work from home. Many of those have left though and I want to put in place a procedure to clean them up. So I basically want to delete anyone who hasn't logged in in the last 60 days or so.
Right now the only way I know to do that is to take each account and manually search in the Logs section of the Smart Console for their username and something like Action:"Log In", with a set interval of the last 2 months, which will give me their last few logins.
Is there a way to run the same log search query from SSH, in expert mode ? If I could do that, I can get a list of users as a text file and write a simple script to run through the whole list.
Thanks for any pointers and Best Regards.
What authentication method is used for these users out of interest - Active Directory, Radius or other?
They use PKCS #12 certificates.
Use the 'fw log' command and grep through the output: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
See also CPLogFilePrint: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Thanks very much for the reply. Unfortunately I had no luck trying to figure out the syntax of a query similar to what I am using in the Smart Console. In the smart console I am simply selecting a date range and entering something like "action:"Log In" username".
You have two issues here:
If you're using R81 and above, you can use the show logs API, which can also be called via the CLI.
This supports queries similar to SmartConsole.
See: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v1.8%20
I've been seeing more customers using API for actions like this recently, If PhoneBoy's Logprint commands dont work out, you might be able to leverage this from another device, through API.
I mentioned that exact API above 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY