- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello, Mates
Is it possible to “observe” all the changes made by an administrator from the CLI of a FW?
For example, if an administrator changes a route, edits an interface, adds a new interface, configures SNMPv2, configures OSPF... all this from the CLI of a FW...
Is it possible to review this activity performed by an administrator in the logs? Or is it stored somewhere else on the device?
Thanks for your comments.
Hey bro,
Smart console changes would be via audit logs, but something like what you described probably either smart event, or /var/log/audit dir.
Andy
On a second thought bro, I know our company uses syslog server for these things, when say someone logs into the firewall, we do get an alert about it.
Andy
Otherwise you would check /var/log/messages
Hi, @Chris_Atkinson
Does this configuration shown in your image also apply when changes are made via CLI on a firewall?
If a change is successful, for example when you “delete” several VLANs, should we be able to see these changes in the SmartConsole Audit Logs?
Hey brother...keep in mind, those changes will NOT show up in smart console audit logs, because thats ONLY for changes made in smart console by default. However, you can make it work the way @Chris_Atkinson posted, you just need to add mgmt server in remote system logging tab. Im sure you know that by default, fw logs will be sent to the management, but not ones you are referring to, unless you set this up first.
I had done that before in the lab and was fine.
Andy
The audit logs are explicitly for any changed made by CLI on the system. So yes. We recommend you send them to syslog and then configure central syslog server to store them all in one place, so save you having to trawl the messages files on the systems and hope the entries you want haven't rotated away.
You need to implement sk99134 or you will not know what your privileged users are doing
/Henrik
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY