Collecting Log Files

Before you run the APG CLI analysis, you must collect log files for the analysis. You can do this with, either:

  • The Check Point log collector (st_apg_collect) to collect and filter Check Point logs so that you can limit Check Point log collection by rule UID or action (drop/accept), and/or by policy package and/or by gateway.
  • The standard log file format that you can prepare from any firewall log file.

If you create an APG job in SecureTrack, you can configure the job to collect logs directly from the device so that you can analyze future traffic.