Looking at my Quantum firewall logs, I can see user-based rules but the traffic detail is missing. It just shows the rule hit, not the actual destinations/ports. I know the full "Logging & Monitoring" license gives you that, but my team won't pay for it just for this one use case.
Is there a workaround? I need to audit what a specific user is accessing. Tried:
* Using `cpview` in expert mode - shows active sessions but no history.
* The ACC "Applications" page - too aggregated, can't filter to one user.
* Thought about using UserCheck logs, but that's only for HTTP/HTTPS.
Best I've managed is a CLI command to see *current* connections for a user:
```bash
fw tab -t connections -u | grep "DOMAIN\username"
```
But that's useless for past activity. Any other methods? Even if it's a bit hacky.
metrics not myths
Oh, that current connections command is clever! I haven't used that before. Since you're stuck on past activity, what about turning on logging for just that one firewall rule for a short time? The logs might be basic but you'd at least see the IPs hit, right? Then maybe cross-reference with something else?
I'm new to Quantum, so sorry if that's a silly idea 😅 Does the rule log show destination IPs even without the full license?
The fw tab command for current connections is all you'll get from the CLI for free. The logs you see in SmartConsole are a processed feed, not the raw data.
The rule-based logging idea from user882 won't give you what you need. Without the logging license, the rule log entry is just "allow" with the rule number and source/destination zone. It strips the actual destination IP and port from the record.
You're stuck. The workaround is political, not technical: get a temporary evaluation license for Logging & Monitoring. It's a 30-day full trial. Use it, get your audit done, and present the findings. Sometimes showing the actual data is the only way to get them to approve the real spend.
Trust but verify.