- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I've been building a script that uses Management API to gather some information regarding logs.
I was trying to use the filter rule_uid, to just see logs regarding one specific rule, but no matter what uid I use, I never get results. I can just search for the UID of the rule with no key information, and it looks like only logs from that rule appear, however I would feel more confident if I could use a key:value filter to guarantee that I only get the logs I require (I attached photos of the filter results in the post).
I know about the rule:<number of rule> filter, but I have multiple policies, so multiple rules number 1, 2, 3 etc... I could match that with the origin or something like that, but my life would be a lot easier if the filter rule_uid just worked.
Am I using the filter correctly? Anyone else knows of a key:value filter that would give me all logs of a specific rule, and that doesn't rely on repeatable values, like rule number or rule name?
Regards,
Rafael Santiago
I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.
layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)
Im fairly sure it only works with UID itself, not rule_uid: flag, but I could be mistaken. Let me play around with it in the lab and will update you.
You might be right. It is weird that we would have a rule_uid filter that doesn´t work though, even though it is hidden under the Other fields option. Perhaps a leftover from previous versions.
Either way thank you for testing.
Regards,
Rafael Santiago
I think I got it...see below. Its a bit odd, since that field is NOT listed in log search options in smart console.
layer_uuid_rule_uuid:(*_b4df506d-1437-4248-958a-7c6f80dd91a3)
Perfect, it also works on my end.
The filter they show doesn't work but this hidden filter does 😅.
Thanks for the help!
Regards,
Rafael Santiago
If you want me to test anything else in the lab, please let me know. I have really good R82 lab that manages both R82 and R81.20 clusters, as well as dedicated R82 smart event server, so its super convenient for any testing.
of course mate! We all work as a team to find the solution, happy we can help.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY