1) Copy attached files to your archiver using winscp for ex.
2) Cd to the directory where the files exist
3) chmod +x saget.py
4) If you want to see all the options of the script please run the below:
./saget.py -help
5) To extract logs Run the below:
./saget.py -L -t x.x.x.x -p 50108 -u admin -s "2015-Dec-01 12:00:00" -e "2015-Dec-20 12:00:00" -o rawlogs.log -q "did exists"
6) you will be prompted to enter a password, enter the password
7) All logs are written to the same directory rawlogs.log file.
2) admin is the REST user admin to check that this admin password is correct:
- NwConsole then press enter
- login localhost:50008 admin
- Type in the password.
- you should be successfully connected in that step
3) After -s "put here the start date of your needed logs"
4) After -e "put here the end date of your needed logs"
5) After -q " put here the query you want to run"
Some examples of your queries:
-q "device.class='firewall'"
-q "did exists"
-q "ip.address='x.x.x.x'"
Related Articles
How to extract the contents of a unix pkg file without installing it. 7Number of Views Unable to extract account data to csv file in RSA Identity Governance & Lifecycle 13Number of Views Silvertail/RSA WTD: how to extract a single binary from an rpm package (for patching) 12Number of Views How to extract parse certificates and private keys from PKCS #12 files using OpenSSL 167Number of Views RSA MFA Agent 2.2.1 for Microsoft Windows Installation and Administration Guide 85Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS