- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Basically I like to see where details on SAM rule for user/admin who created SAM rules are stored (Not the IPs which are blocked)
I have tried to see Audit Logs, Log, Messaged Files from GW and SMS but no luck. And SAM.DAT fire is Binary file .
I think audit log should show you that if you search for time frame and rule name.
Incase to see issue in detail Please see video :
According to sk112061: How to create and view Suspicious Activity Monitoring (SAM) Rules, this is only possible if:
- SAM CLI is used
- fw sam is used with option
| -e <key=val>+ |
Specifies rule information based on the keys and the provided values.
|
so the originator is included
---> So what you want can be achieved if SAM rules are only created by CLI scripts embedding the originator
@PhoneBoy any suggestions here ?
If the commands were set using fw sam on the CLI within the standard clish shell, you'll see evidence of this in /var/log/messages like so:
Sep 1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Start executing : fw sam ... (cmd md5: 70c66e959afe845950934f11615fff55)
Sep 1 13:26:13 2022 R8120EA clish[30380]: cmd by admin: Processing : fw sam -D (cmd md5: 70c66e959afe845950934f11615fff55)
If it was done in SmartConsole, you might find evidence in the Audit logs in SmartConsole (haven't checked).
If it was done via expert mode, unless you've taken steps to explicitly log commands entered there, or you did something like @G_W_Albrecht pointed you to, that information is not logged anywhere, at least as far as I know.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 16 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY