check_point.mgmt.cp_mgmt_show_logs module – Showing logs according to the given filter.

Note

This module is part of the check_point.mgmt collection (version 5.2.3).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install check_point.mgmt.

To use it in a playbook, specify: check_point.mgmt.cp_mgmt_show_logs.

New in check_point.mgmt 2.0.0

Synopsis

  • Showing logs according to the given filter.

  • All operations are performed over Web Services API.

Parameters

Parameter

Comments

auto_publish_session

boolean

Publish the current session if changes have been performed after task completes.

Choices:

  • false ← (default)

  • true

ignore_warnings

boolean

Ignore warnings if exist.

Choices:

  • false

  • true

new_query

dictionary

Running a new query.

custom_end

string

This option is only applicable when using the custom time-frame option.

custom_start

string

This option is only applicable when using the custom time-frame option.

filter

string

The filter as entered in SmartConsole/SmartView.

log_servers

list / elements=string

List of IP’s of logs servers to query.

max_logs_per_request

integer

Limit the number of logs to be retrieved.

time_frame

string

Specify the time frame to query logs.

Choices:

  • "last-7-days"

  • "last-hour"

  • "today"

  • "last-24-hours"

  • "yesterday"

  • "this-week"

  • "this-month"

  • "last-30-days"

  • "all-time"

  • "custom"

top

dictionary

Top results configuration.

count

integer

The number of results to retrieve.

field

string

The field on which the top command is executed.

Choices:

  • "sources"

  • "destinations"

  • "services"

  • "actions"

  • "blades"

  • "origins"

  • "users"

  • "applications"

type

string

Type of logs to return.

Choices:

  • "logs"

  • "audit"

query_id

string

Get the next page of last run query with specified limit.

version

string

Version of checkpoint. If not given one, the latest version taken.

wait_for_task

boolean

Wait for the task to end. Such as publish task.

Choices:

  • false

  • true ← (default)

wait_for_task_timeout

integer

How many minutes to wait until throwing a timeout error.

Default: 30

Examples

- name: show-logs
  cp_mgmt_show_logs:
    new_query:
      filter: blade:"Threat Emulation"
      max_logs_per_request: '2'
      time_frame: today

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

cp_mgmt_show_logs

dictionary

The checkpoint show-logs output.

Returned: always.

Authors

  • Or Soffer (@chkp-orso)