- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Want to monitor, who change/edit the rule/Object i...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Want to monitor, who change/edit the rule/Object in smartconsole.
In my smart console environment, there are several users. They edit and, change the rule as required. By the time, one user edits a log 25 days ago and I want to know who edits that rule by search in future. Is there any option/way to identify which user edits the rule or changes by searching the rule number?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Copy rule UID by right-click on the affected rule number and select "Copy Rule UID"
2. Open Audit Logs and paste copied rule UID into search string
3. Select proper timeframe (all time)
As long as the audit logs are not deleted or overwritten, you should be able to see all actions for affected rule (who and when created that rule, who and when changed that rule, who and when disabled/deleted that rule).
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Copy rule UID by right-click on the affected rule number and select "Copy Rule UID"
2. Open Audit Logs and paste copied rule UID into search string
3. Select proper timeframe (all time)
As long as the audit logs are not deleted or overwritten, you should be able to see all actions for affected rule (who and when created that rule, who and when changed that rule, who and when disabled/deleted that rule).
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Simple way set up a elasticsearch and and filebeat and route your logs from checkpoint mgmt server using cp_log_export with cef forwarder and that way you can create dashboard or setup alerts if you are using opensearch.
This is defacto mechanism I use
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @JozkoMrkvicka
Thank uou so much. Following this, my problem is solved.
