Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
maxtaan
Contributor
Jump to solution

Want to monitor, who change/edit the rule/Object in smartconsole.

In my smart console environment, there are several users. They edit and, change the rule as required. By the time, one user edits a log 25 days ago and I want to know who edits that rule by search in future. Is there any option/way to identify which user edits the rule or changes by searching the rule number?

0 Kudos
1 Solution

Accepted Solutions
JozkoMrkvicka
Mentor
Mentor

1. Copy rule UID by right-click on the affected rule number and select "Copy Rule UID"

2. Open Audit Logs and paste copied rule UID into search string

3. Select proper timeframe (all time)

As long as the audit logs are not deleted or overwritten, you should be able to see all actions for affected rule (who and when created that rule, who and when changed that rule, who and when disabled/deleted that rule).

Kind regards,
Jozko Mrkvicka

View solution in original post

0 Kudos
3 Replies
JozkoMrkvicka
Mentor
Mentor

1. Copy rule UID by right-click on the affected rule number and select "Copy Rule UID"

2. Open Audit Logs and paste copied rule UID into search string

3. Select proper timeframe (all time)

As long as the audit logs are not deleted or overwritten, you should be able to see all actions for affected rule (who and when created that rule, who and when changed that rule, who and when disabled/deleted that rule).

Kind regards,
Jozko Mrkvicka
0 Kudos
Blason_R
Leader
Leader

Simple way set up a elasticsearch and and filebeat and route your logs from checkpoint mgmt server using cp_log_export with cef forwarder and that way you  can create dashboard or setup alerts if you are using opensearch.

This is defacto mechanism I use

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
maxtaan
Contributor

Hello @JozkoMrkvicka 

Thank uou so much. Following this, my problem is solved.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events