Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
asher
Contributor
Jump to solution

check if host access Internet last 30 days automation

Hello

 

we upgrade Management to R80.40 ( smart1 appliances) 

we have also dedicated appliance for LOG SERVER. we have Mounty Phyton script that use API

for list Host and ip object that member in Network group with access to internet. the groups has a Tags , and with api we get all members on each TAGED group,

we want to add also option that look for last time each object is access to internet ( should be traffic to specific PROXY ip address )

its possible ?

the api version is 1.6.1 

in other words i need find way to query last 30 days that each object made traffic with 8080 to PROXY ip address with accepted action

0 Kudos
1 Solution

Accepted Solutions
Maik
Advisor

You could try to accomplish something with third party tools and the log exporter

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

However, for your use-case the api should be the way to go. As far as I understand you are able to filter with the "filter" argument...

grafik.png

In fact it seems to be exactly the same filters that you use when you access your logs via the SmartConsole logging section.

Unfortunately I am not able to test this as I do not have a matching R80.40 or R81 deployment.

View solution in original post

0 Kudos
4 Replies
Maik
Advisor

Hey,

I did not use this feature yet, however with api version 1.6.1 which got introduced with R80.40 JHF Take 78 you are actually able to use the mgmt api in order to search for log entries.

As far as I understand the documentation it should be possible to achieve exactly what you want with this feature:

https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-logs~v1.6.1%20

[Of course you need to enable logging in the rules for the respective traffic]

Regards,

Maik

0 Kudos
asher
Contributor

I read that documentation but there is no filter by source ip and Destination ip 

if there is other idea also without API ?

0 Kudos
Maik
Advisor

You could try to accomplish something with third party tools and the log exporter

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

However, for your use-case the api should be the way to go. As far as I understand you are able to filter with the "filter" argument...

grafik.png

In fact it seems to be exactly the same filters that you use when you access your logs via the SmartConsole logging section.

Unfortunately I am not able to test this as I do not have a matching R80.40 or R81 deployment.

0 Kudos
asher
Contributor

yes its correct the filter is same as search on console, its not explained on the KB

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events