<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update' in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240951#M450</link>
    <description>&lt;P&gt;While I heard about this in the context of EPMaaS customers, Smart-1 Cloud customers also have similar limits that I assume will be enforced in the near future.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 19:54:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-11T19:54:08Z</dc:date>
    <item>
      <title>Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240676#M427</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have a customer who is receiving emails from Checkpoint that their log ingestion rate is exceeding 50Gb and that they need to buy more storage.&lt;/P&gt;&lt;P&gt;This started from December - the log ingestion graph shows a flat line of nothing and then it explodes.&lt;/P&gt;&lt;P&gt;The customer is unaware of any changes in the environment.&lt;/P&gt;&lt;P&gt;It references two SK;&lt;/P&gt;&lt;P&gt;SK181096 - How to optimize cloud logs&lt;/P&gt;&lt;P&gt;SK182394 - Cloud log analytic &amp;amp; logging - ingestion/Retention solution.&lt;/P&gt;&lt;P&gt;For the second SK I'm not sure that customers have access to the product catalog(?)&lt;/P&gt;&lt;P&gt;For the first SK we followed the steps to identify the logs with a view to tuning the policy.&lt;/P&gt;&lt;P&gt;However when we filter as described we find that the logs are 100% Low Severity, 98.5% Event type update, 70.63% anti malware blade.&lt;/P&gt;&lt;P&gt;As such there is no matching rule so we cant follow the advice in the SK, we cant see how to prevent this log type from being ingested - does anyone have any ideas?&lt;/P&gt;&lt;P&gt;They are on E88.32.2003.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 09:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240676#M427</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2025-02-07T09:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240678#M428</link>
      <description>&lt;P&gt;yes, i will second that... starting about a week ago , we also started seeing this on some of our customers too. Sorry i dont have an answer for you.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 10:25:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240678#M428</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2025-02-07T10:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240680#M429</link>
      <description>&lt;P&gt;thanks for confirming! nice to know its not isolated - well its not 'nice' its happening elsewhere but its at least a sanity check &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 11:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240680#M429</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2025-02-07T11:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240910#M444</link>
      <description>&lt;P&gt;We see exact the same this behavior. No change of the logs since a year, but now these messages. Something changed in the background ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240910#M444</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-02-11T14:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240940#M447</link>
      <description>&lt;P&gt;As a bit of background, EPMaaS tenants have a limit on the amount of logs that are allowed to be ingested.&lt;BR /&gt;We do not enforce these limits currently, but are expecting to start doing so&amp;nbsp;by the end of Q1.&lt;BR /&gt;This is why you are starting to see notifications about it in Infinity Portal.&lt;BR /&gt;This is not 100% finalized, so the details might change.&lt;/P&gt;
&lt;P&gt;More relevant to the accuracy of the notification itself, it appears (per TAC)&amp;nbsp;the ingestion volume does not seem to be calculating correctly on all tenants.&lt;BR /&gt;This is under investigation.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 17:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240940#M447</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T17:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240945#M448</link>
      <description>&lt;P&gt;Noticed that as well in the portal for few customers.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 17:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240945#M448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-11T17:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240949#M449</link>
      <description>&lt;P&gt;We see this not not only for EPMaaS customer. Some Smart1-cloud tenants have the same behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 19:37:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240949#M449</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-02-11T19:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240951#M450</link>
      <description>&lt;P&gt;While I heard about this in the context of EPMaaS customers, Smart-1 Cloud customers also have similar limits that I assume will be enforced in the near future.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 19:54:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240951#M450</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T19:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240952#M451</link>
      <description>&lt;P&gt;Noticed the same for 2 S1C cloud clients as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 19:56:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240952#M451</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-11T19:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Infinity log ingestion rate has suddenly and dramatically increased for AM 'event type update'</title>
      <link>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240953#M452</link>
      <description>&lt;P&gt;The page to check log usage definitely looks different in the portal now.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 20:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Infinity-log-ingestion-rate-has-suddenly-and-dramatically/m-p/240953#M452</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-11T20:07:23Z</dc:date>
    </item>
  </channel>
</rss>

