Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RafaelSantiago
Participant
Jump to solution

Using rule_uid filter in log search

Hi all,

I've been building a script that uses Management API to gather some information regarding logs.

I was trying to use the filter rule_uid, to just see logs regarding one specific rule, but no matter what uid I use, I never get results. I can just search for the UID of the rule with no key information, and it looks like only logs from that rule appear, however I would feel more confident if I could use a key:value filter to guarantee that I only get the logs I require (I attached photos of the filter results in the post).


I know about the rule:<number of rule> filter, but I have multiple policies, so multiple rules number 1, 2, 3 etc... I could match that with the origin or something like that, but my life would be a lot easier if the filter rule_uid just worked.

Am I using the filter correctly? Anyone else knows of a key:value filter that would give me all logs of a specific rule, and that doesn't rely on repeatable values, like rule number or rule name?

Regards,

Rafael Santiago

0 Kudos
1 Solution

Accepted Solutions
the_rock
MVP Diamond
MVP Diamond

I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)

 

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

6 Replies
the_rock
MVP Diamond
MVP Diamond

Im fairly sure it only works with UID itself, not rule_uid: flag, but I could be mistaken. Let me play around with it in the lab and will update you.

Best,
Andy
"Have a great day and if its not, change it"
RafaelSantiago
Participant

You might be right. It is weird that we would have a rule_uid filter that doesn´t work though, even though it is hidden under the Other fields option. Perhaps a leftover from previous versions.

Either way thank you for testing. 

Regards,

Rafael Santiago

the_rock
MVP Diamond
MVP Diamond

I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)

 

Best,
Andy
"Have a great day and if its not, change it"
RafaelSantiago
Participant

Perfect, it also works on my end.

The filter they show doesn't work but this hidden filter does 😅.

Thanks for the help!

Regards,

Rafael Santiago

the_rock
MVP Diamond
MVP Diamond

If you want me to test anything else in the lab, please let me know. I have really good R82 lab that manages both R82 and R81.20 clusters, as well as dedicated R82 smart event server, so its super convenient for any testing.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

of course mate! We all work as a team to find the solution, happy we can help.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events