- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Basically I like to see where details on SAM rule for user/admin who created SAM rules are stored (Not the IPs which are blocked)
I have tried to see Audit Logs, Log, Messaged Files from GW and SMS but no luck. And SAM.DAT fire is Binary file .
I think audit log should show you that if you search for time frame and rule name.
Incase to see issue in detail Please see video :
According to sk112061: How to create and view Suspicious Activity Monitoring (SAM) Rules, this is only possible if:
- SAM CLI is used
- fw sam is used with option
| -e <key=val>+ |
Specifies rule information based on the keys and the provided values.
|
so the originator is included
---> So what you want can be achieved if SAM rules are only created by CLI scripts embedding the originator
@PhoneBoy any suggestions here ?
If the commands were set using fw sam on the CLI within the standard clish shell, you'll see evidence of this in /var/log/messages like so:
Sep 1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Start executing : fw sam ... (cmd md5: 70c66e959afe845950934f11615fff55)
Sep 1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Processing : fw sam -D (cmd md5: 70c66e959afe845950934f11615fff55)
If it was done in SmartConsole, you might find evidence in the Audit logs in SmartConsole (haven't checked).
If it was done via expert mode, unless you've taken steps to explicitly log commands entered there, or you did something like @G_W_Albrecht pointed you to, that information is not logged anywhere, at least as far as I know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY