sk181906 - How to see the API usage on a Management Server?
How to see the API usage on a Management Server?
Solution
Background
You can perform various action on a Check Point Management Server with the Management REST API commands (see the Management API Reference).
You can extract data from the API logs to get the API usage information (API calls, timestamp, duration, payload, and so on).
This feature is available in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 101
Procedure
Connect to the command line on the Security Management Server / Multi-Domain Security Management Server.
Log in to the Expert mode.
On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
mdsenv <IP Address or Name of Domain Management Server>
- Run the script with the applicable parameters:
$FWDIR/scripts/api_log_to_json.py <parameters>
Syntax
| `$FWDIR/scripts/api_log_to_json.py {-h |
$FWDIR/scripts/api_log_to_json.py [-o <output file>] [<API log files> [<API log files> ...]] |
CLI Parameters
| Parameter | Description |
-h--help |
Shows the short built-in help. |
-v--verbose-help |
Shows the verbose built-in help. |
-o <output file>--output <output file> |
Specifies the path to the output file. If not specified, the script shows the output on the screen. |
<API log files> |
Specifies the list of paths to API log files. If not specified, the script analyzes all $MDS_FWDIR/log/api.elg* files. |
Output
The output structure is a list of JSON objects with the fields described below.
The JSON objects are sorted in the order of "inbound_timestamp" and then in the order of "id".
| Field | Description |
command |
Name of the API command. |
id |
Numeric ID of the API request. Requests and responses from the Check Point API log are combined into a single object. Each time you stop and start Check Point services (or reboot) on the Management Server, the ID starts from 1. |
x_chkp_sid |
UUID that all commands from the session share (not a Session UUID). |
inbound_timestamp |
Timestamp of the API request. Format: yyyy-mm-dd hh:mm:ss.sss |
outbound_timestamp |
Timestamp of the API response. Format: yyyy-mm-dd hh:mm:ss.sss |
duration |
Duration of the API call - time between receiving the API request and sending the API response. Format: hh:mm:ss.sss |
inbound_payload |
API request data in the JSON format. |
outbound_payload |
API response data in the JSON format. |
Example for the API " show-object":
[\ {\ "id": 316,\ "x_chkp_sid": "8095012a-4ec3-deab-90f5-ab54a7d36127",\ "command": "show-object",\ "inbound_timestamp": "2023-08-21 18:57:22.062",\ "outbound_timestamp": "2023-08-21 18:57:22.074",\ "duration": "0:00:00.012",\ "inbound_payload": {\ "uid": "4376ea6c-387b-4360-8086-f4c7ffc51b71"\ },\ "outbound_payload": {\ "object": {\ "uid": "4376ea6c-387b-4360-8086-f4c7ffc51b71",\ "name": "host-192.168.3.4",\ "type": "host",\ "domain": {\ "uid": "41e821a0-3720-11e3-aa6e-0800200c9fde",\ "name": "SMC User",\ "domain-type": "domain"\ },\ "icon": "Objects/host",\ "color": "black",\ "ipv4-address": "192.168.3.4"\ }\ }\ },\ ... ... ...\ ]
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access LevelGeneral
StatusApproved by TAC
Date Created2024-01-21
Last Modified2025-05-19