Skip to content

Collect evidence

SegAudit reads the firewall’s configuration and, when you have one, its traffic log from the same period. A configuration alone gives results: its findings show what the rules allow and are marked not verified by traffic. The traffic log adds proof of which paths are actually in use. It never connects to a firewall to get them.

Platform Configuration Traffic log
Panorama or standalone PAN-OS Running configuration (XML) Traffic log (CSV)
FortiGate Configuration backup with passwords masked Forward-traffic log, from the FortiGate or FortiAnalyzer
Cisco ASA show running-config, from a recorded SSH session or ASDM Syslog connection and deny messages, from the syslog server
Cisco FTD managed by FMC FMC export, from the read-only export script (Python or PowerShell) Connection events as syslog, from the syslog server
Check Point (Security Management Server, R81.10 to R82) Check Point export, from the read-only export script (Python or PowerShell) Firewall logs, from the same script or the syslog server Log Exporter sends to

Evidence request, under Data in the app, writes the export instructions for your engineer with your device names and window filled in, for the web interface, a script or the CLI on Windows, macOS or Linux. Optional export scripts in Python and PowerShell collect both files read-only and print their SHA-256.

A week of traffic shows what is in use. Ask for 30 days or more when the work will retire rules that look unused.

Licensed customers can read the full export guide for each platform, with the access each script needs, in the customer guides. Supported versions are on firewall support.