Logging, SmartEvent, Management API & Automation

Check Point — CCSA track EVE-NG — Check Point VM (SmartConsole + CLI)

مقصدObjectiveObjective

لاگ تجزیے کے لیے SmartLog استعمال کریں، SmartEvent correlation سمجھیں، اور بنیادی Management API (mgmt_cli) automation کریں۔Log analysis ke liye SmartLog use karein, SmartEvent correlation samjhein, aur basic Management API (mgmt_cli) automation karein.Use SmartLog for log analysis, understand SmartEvent correlation, and perform basic Management API (mgmt_cli) automation.

آسان مثالSimple AnalogySimple Analogy

سی سی ٹی وی کنٹرول روم بمعہ روبوٹ اسسٹنٹ کی طرح: SmartLog لائیو کیمرہ دیوار ہے، SmartEvent وہ تجزیہ کار ہے جو نمونے پہچانتا ہے، اور Management API وہ روبوٹ ہے جو حکم پر تالے بدلتا ہے۔CCTV control room plus robot assistant ki tarah: SmartLog live camera wall hai, SmartEvent woh analyst hai jo patterns pehchanta hai, aur Management API woh robot hai jo command par locks badalta hai.Like a CCTV control room plus a robot assistant: SmartLog is the live camera wall, SmartEvent is the analyst who spots patterns, and the Management API is the robot that changes the locks on command.

سیٹ اپLab SetupLab Setup

EVE-NG مینجمنٹ گیٹ وے سے لاگز کے ساتھ؛ SmartConsole Logs & Monitor view؛ mgmt_cli کے لیے مینجمنٹ سرور پر expert-mode CLI۔EVE-NG management gateway se logs ke saath; SmartConsole Logs & Monitor view; mgmt_cli ke liye management server par expert-mode CLI.EVE-NG management with logs flowing from the gateway; SmartConsole Logs & Monitor view; expert-mode CLI on the management server for mgmt_cli.

اقداماتStepsSteps

Step 1

SmartLog سے تحقیق کریں: لاگز کو blade، action یا rule سے فلٹر کریں، اور ہر event کا matched rule اور صارف پڑھیں۔ لاگز آپ کا پہلا troubleshooting ٹول ہیں۔SmartLog se investigate karein: logs ko blade, action ya rule se filter karein, aur har event ka matched rule aur user parhein. Logs aap ka pehla troubleshooting tool hain.Investigate with SmartLog: filter logs by blade, action, or rule, and read the matched rule and user for each event. Logs are your first troubleshooting tool.

🖱️ Logs & Monitor > Logs: blade=IPS یا action=Drop سے فلٹر کریں؛ Rule، User اور Blade کالم شامل کریں تاکہ سمجھ آئے کیا ہوا۔Logs & Monitor > Logs: blade=IPS ya action=Drop se filter karein; Rule, User aur Blade columns add karein taake samajh aaye kya hua.Logs & Monitor > Logs: filter by blade=IPS or action=Drop; add columns for Rule, User, and Blade to read what happened.

Step 2

SmartEvent کھولیں: یہ خام لاگز کو 'possible bot infection' جیسے events میں جوڑتا ہے timelines کے ساتھ۔ اس طرح آپ وہ نمونے پکڑتے ہیں جو کوئی ایک لاگ نہیں دکھاتا۔SmartEvent kholein: yeh raw logs ko 'possible bot infection' jaise events mein correlate karta hai timelines ke saath. Is tarah aap woh patterns pakarte hain jo koi ek log nahi dikhata.Open SmartEvent: it correlates raw logs into events like 'possible bot infection' with timelines. This is how you spot patterns no single log reveals.

🖱️ Logs & Monitor > SmartEvent: ڈیش بورڈ کھولیں، top attackers، top victims اور مربوط سیکیورٹی events چیک کریں۔Logs & Monitor > SmartEvent: dashboard kholein, top attackers, top victims aur correlated security events check karein.Logs & Monitor > SmartEvent: open the dashboard, check top attackers, top victims, and any correlated security events.

Step 3

mgmt_cli سے Management API میں لاگ اِن کریں اور گیٹ وے آبجیکٹس کی فہرست دیکھیں۔ API sessions SmartConsole کلکس کا scriptable ورژن ہیں۔mgmt_cli se Management API mein login karein aur gateway objects list karein. API sessions SmartConsole clicks ka scriptable version hain.Log in to the Management API with mgmt_cli and list gateway objects. API sessions are the scriptable version of SmartConsole clicks.

mgmt_cli -r true login > id.txt
mgmt_cli -s id.txt show gateways-and-servers limit 5

Step 4

API سے host آبجیکٹ بنائیں اور تبدیلی شائع کریں۔ Publish SmartConsole میں Publish کلک کرنے کے برابر ہے — غیر شائع شدہ تبدیلیاں کبھی پالیسی تک نہیں پہنچتیں۔API se host object banayein aur change publish karein. Publish SmartConsole mein Publish click karne ke barabar hai — unpublished changes kabhi policy tak nahi pahunchte.Create a host object via API and publish the change. Publish is the API equivalent of clicking Publish in SmartConsole — unpublished changes never reach the policy.

mgmt_cli -s id.txt add host name lab-test-host ipv4-address 10.0.1.99
mgmt_cli -s id.txt publish

Step 5

API سے access rule شامل کریں، شائع کریں، اور لاگ آؤٹ کریں۔ آپ نے کوڈ سے وہی کیا جو GUI کرتا ہے — خودکار، جائزہ شدہ فائر وال تبدیلیوں (اور Zero Trust orchestration) کی بنیاد۔API se access rule add karein, publish karein, aur logout karein. Aap ne code se wohi kiya jo GUI karta hai — automated, reviewed firewall changes (aur Zero Trust orchestration) ki bunyad.Add an access rule via API, publish, and log out. You just did through code what the GUI does — the basis for automated, reviewed firewall changes (and Zero Trust orchestration).

mgmt_cli -s id.txt add access-rule layer "Network" position top name "API-created test rule" source lab-test-host destination Any action Drop track "Log"
mgmt_cli -s id.txt publish
mgmt_cli -s id.txt logout

تصدیقVerifyVerify

SmartLog فلٹر شدہ events دکھائے، SmartEvent ڈیش بورڈ مربوط events دکھائے، اور آپ کا API سے بنایا host اور rule SmartConsole میں موجود ہوں۔SmartLog filtered events dikhaye, SmartEvent dashboard correlated events dikhaye, aur aap ka API-created host aur rule SmartConsole mein maujood hon.SmartLog shows filtered events, SmartEvent dashboard displays correlated events, and your API-created host and rule exist in SmartConsole.

mgmt_cli -r true login
cpstat mg

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ گیٹ وے سے لاگز نہیں آ رہے۔Gateway se logs nahi aa rahe.No logs arriving from the gateway.

✅ گیٹ وے اور مینجمنٹ (یا لاگ سرور) کے درمیان SIC/logging connectivity چیک کریں، گیٹ وے آبجیکٹ پر لاگ ترتیبات کی تصدیق کریں، اور لاگ سرور پر ڈسک کی جگہ دیکھیں۔Gateway aur management (ya log server) ke darmiyan SIC/logging connectivity check karein, gateway object par log settings confirm karein, aur log server par disk space verify karein.Check SIC/logging connectivity between gateway and management (or log server), confirm the log settings on the gateway object, and verify disk space on the log server.

⚠️ mgmt_cli لاگ اِن ناکام ہو جاتا ہے۔mgmt_cli login fail ho jata hai.mgmt_cli login fails.

✅ تصدیق کریں کہ API مینجمنٹ سرور پر چالو ہے (API ترتیبات)، درست credentials استعمال کریں، اور چیک کریں کہ مینجمنٹ سرور کے access rules API ٹریفک allow کرتے ہیں۔Verify karein ke API management server par enabled hai (API settings), sahi credentials use karein, aur check karein ke management server ke access rules API traffic allow karte hain.Verify the API is enabled on the management server (API settings), use correct credentials, and check the management server's own access rules allow API traffic.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ SmartLog بمقابلہ SmartEvent — فرق کیا ہے؟SmartLog vs SmartEvent — farq kya hai?SmartLog vs SmartEvent — what's the difference?

SmartLog/SmartView خام لاگ دیکھنے والے ہیں؛ SmartEvent لاگز کو جوڑ کر سیکیورٹی events، ڈیش بورڈز اور رپورٹس بناتا ہے — یہ لاکھوں لاگز کو 'یہ ہوسٹ متاثر ہے' نتائج میں بدلتا ہے۔SmartLog/SmartView raw log viewers hain; SmartEvent logs ko correlate karke security events, dashboards aur reports banata hai — yeh lakhon logs ko 'yeh host infected hai' natijon mein badalta hai.SmartLog/SmartView are the raw log viewers; SmartEvent correlates logs into security events, dashboards, and reports — it turns millions of logs into 'this host is infected' conclusions.

❓ Check Point Management API سے کیا کر سکتے ہیں؟Check Point Management API se kya kar sakte hain?What can you do with the Check Point Management API?

Management API (mgmt_cli / REST) اسکرپٹس کو لاگ اِن، آبجیکٹس بنانا، رولز بدلنا، پالیسی انسٹال کرنا اور تبدیلیاں شائع کرنے دیتی ہے — automation، CI/CD فائر وال تبدیلیوں، اور Zero Trust orchestration کی بنیاد۔Management API (mgmt_cli / REST) scripts ko login, objects banana, rules badalna, policy install karna aur changes publish karne deti hai — automation, CI/CD firewall changes, aur Zero Trust orchestration ki bunyad.The Management API (mgmt_cli / REST) lets scripts log in, create objects, change rules, install policy, and publish changes — the foundation for automation, CI/CD firewall changes, and Zero Trust orchestration.