Friday, January 25, 2019

How to find out sg-commands that was issued on a Forcepoint NGFW

To find out a basic wildcard  search for commands issues on a NGFW you can use a "*" during the a log browser query.

The  filter type is "Information Message:" . In this example I've inserted the following sg-*

See screenshot;


Log browser querying is very easily execute and audit tracing is simple as 1-2-3






NSE ( network security expert) and Route/Switching Engineer
kfelix  -----a----t---- socpuppets ---dot---com
     ^      ^
=(  @  @ )=
         o
        /  \

No comments:

Post a Comment