# How to see the API usage on a Management Server?

## Solution

### Background

You can perform various action on a Check Point Management Server with the Management REST API commands (see the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction)).

You can extract data from the API logs to get the API usage information (API calls, timestamp, duration, payload, and so on).

This feature is available in:

- [Check Point Quantum R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 101

### Procedure

1. Connect to the command line on the Security Management Server / Multi-Domain Security Management Server.

2. Log in to the Expert mode.

3. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:

`mdsenv <IP Address or Name of Domain Management Server>`

4. Run the script with the applicable parameters:

`$FWDIR/scripts/api_log_to_json.py <parameters>`

### Syntax

|     |
| --- |
| `$FWDIR/scripts/api_log_to_json.py {-h | -v}` |
| `$FWDIR/scripts/api_log_to_json.py [-o <output file>] [<API log files> [<API log files> ...]]` |

**CLI Parameters**

|     |     |
| --- | --- |
| Parameter | Description |
| `-h`<br>`--help` | Shows the short built-in help. |
| `-v`<br>`--verbose-help` | Shows the verbose built-in help. |
| `-o <output file>`<br>`--output <output file>` | Specifies the path to the output file.<br>If not specified, the script shows the output on the screen. |
| `<API log files>` | Specifies the list of paths to API log files.<br>If not specified, the script analyzes all _$MDS\_FWDIR/log/api.elg\*_ files. |

### Output

The output structure is a list of JSON objects with the fields described below.

The JSON objects are sorted in the order of "`inbound_timestamp`" and then in the order of "`id`".

|     |     |
| --- | --- |
| Field | Description |
| `command` | Name of the API command. |
| `id` | Numeric ID of the API request.<br>Requests and responses from the Check Point API log are combined into a single object.<br>Each time you stop and start Check Point services (or reboot) on the Management Server, the ID starts from 1. |
| `x_chkp_sid` | UUID that all commands from the session share (not a Session UUID). |
| `inbound_timestamp` | Timestamp of the API request.<br>Format: _yyyy-mm-dd hh:mm:ss.sss_ |
| `outbound_timestamp` | Timestamp of the API response.<br>Format: _yyyy-mm-dd hh:mm:ss.sss_ |
| `duration` | Duration of the API call - time between receiving the API request and sending the API response.<br>Format: _hh:mm:ss.sss_ |
| `inbound_payload` | API request data in the JSON format. |
| `outbound_payload` | API response data in the JSON format. |

Example for the API " _show-object_":

> ```
> [\
>     {\
>       "id": 316,\
>       "x_chkp_sid": "8095012a-4ec3-deab-90f5-ab54a7d36127",\
>       "command": "show-object",\
>       "inbound_timestamp": "2023-08-21 18:57:22.062",\
>       "outbound_timestamp": "2023-08-21 18:57:22.074",\
>       "duration": "0:00:00.012",\
>       "inbound_payload": {\
>         "uid": "4376ea6c-387b-4360-8086-f4c7ffc51b71"\
>       },\
>       "outbound_payload": {\
>         "object": {\
>           "uid": "4376ea6c-387b-4360-8086-f4c7ffc51b71",\
>           "name": "host-192.168.3.4",\
>           "type": "host",\
>           "domain": {\
>             "uid": "41e821a0-3720-11e3-aa6e-0800200c9fde",\
>             "name": "SMC User",\
>             "domain-type": "domain"\
>           },\
>           "icon": "Objects/host",\
>           "color": "black",\
>           "ipv4-address": "192.168.3.4"\
>         }\
>       }\
>     },\
>     ... ... ...\
> ]
> ```

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access LevelGeneral  
StatusApproved by TAC  
Date Created2024-01-21  
Last Modified2025-05-19
