<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.cpwiki.net/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.cpwiki.net/index.php?action=history&amp;feed=atom&amp;title=fw_audit_log_parsing_via_CLI</id>
		<title>fw audit log parsing via CLI - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.cpwiki.net/index.php?action=history&amp;feed=atom&amp;title=fw_audit_log_parsing_via_CLI"/>
		<link rel="alternate" type="text/html" href="http://www.cpwiki.net/index.php?title=fw_audit_log_parsing_via_CLI&amp;action=history"/>
		<updated>2026-04-29T10:11:12Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.21.10</generator>

	<entry>
		<id>http://www.cpwiki.net/index.php?title=fw_audit_log_parsing_via_CLI&amp;diff=206&amp;oldid=prev</id>
		<title>Nighthawk at 14:14, 21 August 2013</title>
		<link rel="alternate" type="text/html" href="http://www.cpwiki.net/index.php?title=fw_audit_log_parsing_via_CLI&amp;diff=206&amp;oldid=prev"/>
				<updated>2013-08-21T14:14:48Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 14:14, 21 August 2013&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;parse&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;parse&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; fw log -ln -s &amp;quot;Aug 19,2013 21:45:00&amp;quot; -e &amp;quot;Aug 20,2013 23:59:00&amp;quot; fw.adtlog | awk -F &amp;quot;;&amp;quot; '{for (i=1; i&amp;lt;=NF; i++) printf $i &amp;quot;\n&amp;quot;}'&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# &lt;/ins&gt;fw log -ln -s &amp;quot;Aug 19,2013 21:45:00&amp;quot; -e &amp;quot;Aug 20,2013 23:59:00&amp;quot; fw.adtlog | awk -F &amp;quot;;&amp;quot; '{for (i=1; i&amp;lt;=NF; i++) printf $i &amp;quot;\n&amp;quot;}'&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;example output...&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; 19Aug2013 21:53:01 accept 192.168.1.1 &amp;lt;&amp;#160; &amp;#160; ObjectName: test_group_object&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; 19Aug2013 21:53:01 accept 192.168.1.1 &amp;lt;&amp;#160; &amp;#160; ObjectName: test_group_object&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Nighthawk</name></author>	</entry>

	<entry>
		<id>http://www.cpwiki.net/index.php?title=fw_audit_log_parsing_via_CLI&amp;diff=205&amp;oldid=prev</id>
		<title>Nighthawk: Created page with &quot;Log entries and field changes are separated by semicolons in the fw.adtlog file.  It is very difficult to read, even  with the smartview tracker.  The command line below run o...&quot;</title>
		<link rel="alternate" type="text/html" href="http://www.cpwiki.net/index.php?title=fw_audit_log_parsing_via_CLI&amp;diff=205&amp;oldid=prev"/>
				<updated>2013-08-21T14:14:14Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;Log entries and field changes are separated by semicolons in the fw.adtlog file.  It is very difficult to read, even  with the smartview tracker.  The command line below run o...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Log entries and field changes are separated by semicolons in the fw.adtlog file.  It is very difficult to read, even &lt;br /&gt;
with the smartview tracker.  The command line below run on the SmartCenter or from a CMA environment will output the log file in an easy to read format to terminal.&lt;br /&gt;
&lt;br /&gt;
parse&lt;br /&gt;
 fw log -ln -s &amp;quot;Aug 19,2013 21:45:00&amp;quot; -e &amp;quot;Aug 20,2013 23:59:00&amp;quot; fw.adtlog | awk -F &amp;quot;;&amp;quot; '{for (i=1; i&amp;lt;=NF; i++) printf $i &amp;quot;\n&amp;quot;}'&lt;br /&gt;
&lt;br /&gt;
 19Aug2013 21:53:01 accept 192.168.1.1 &amp;lt;    ObjectName: test_group_object&lt;br /&gt;
  ObjectType: network_object_group&lt;br /&gt;
  ObjectTable: network_objects&lt;br /&gt;
  Operation: Modify Object&lt;br /&gt;
  Uid: {F7F0772C-0917-11E3-8A4F-ABB20701CFCF}&lt;br /&gt;
  Administrator: jsmith&lt;br /&gt;
  Machine: lab-mds&lt;br /&gt;
  FieldsChanges: test_group_object: added 'test_client' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[category:logging]]&lt;/div&gt;</summary>
		<author><name>Nighthawk</name></author>	</entry>

	</feed>