[logs] Re: Check Point FW1 Log

From: Jim Clausing (clausing@private)
Date: Sun Feb 19 2006 - 13:35:10 PST


You can use 'fw logexport' to dump the binary log out in ascii (; 
separated if memory serves) then you can use grep or whatever other tool 
you want to search the logs and pull out the stuff you are interested in.

--
Jim Clausing
GCFA, GCIA, GCFW, GSIP, GSOC, GREM, CISSP, CCSA

On or about Sat, 18 Feb 2006, Greg Dotoli pontificated thusly:

> Does anyone know of a command line tool for searching
> through  a proprietary FW1 log?
> We want to setup a stand alone station for searching
> through syslogs and log files from various firewalls.
> I can't seem to find a tool for the FW1 binary log. I
> know checkpoint allows command level searching on
> the active firewall, but these files have been moved
> to a central server.
>  
> Now we need to move the binary logs to our station for
> log analysis.
>  
> Thanks,
>  
> Gregg
> _______________________________________________
> LogAnalysis mailing list
> LogAnalysis@private
> http://lists.shmoo.com/mailman/listinfo/loganalysis
> 
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Mon Feb 20 2006 - 00:58:17 PST