<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use Event Fields in automatic reaction on R80.10? in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5565#M100975</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to setup some SNMP traps as automatic reactions on R80.10 SmartEvent. It doesn't seem to&amp;nbsp;work the same way as it did in R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fields like&amp;nbsp;&lt;SPAN&gt;[Source] and [Destination] have an array of sub-fields which can be seen when using a script to print it:&amp;nbsp;Destination: (countryname: United States; IP: 216.58.222.98; repetitions: 1). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thus, when the host has a public IP address it returns only the countryname in the trap.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, the field [Origin] always returns the IP as "0", but I could really work with the second sub-field "hostname":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Origin: (IP: 0; hostname: SMS; repetitions: 1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to put&amp;nbsp;these&amp;nbsp;sub-fields in the trap using some variation of the notation [&amp;lt;field&amp;gt;]?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The alternative would be to create a script to filter the event output and send these traps, but I'd rather not have to install scripts every time I need to set these up.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Aug 2017 14:19:07 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2017-08-23T14:19:07Z</dc:date>
    <item>
      <title>How to use Event Fields in automatic reaction on R80.10?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5565#M100975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to setup some SNMP traps as automatic reactions on R80.10 SmartEvent. It doesn't seem to&amp;nbsp;work the same way as it did in R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fields like&amp;nbsp;&lt;SPAN&gt;[Source] and [Destination] have an array of sub-fields which can be seen when using a script to print it:&amp;nbsp;Destination: (countryname: United States; IP: 216.58.222.98; repetitions: 1). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thus, when the host has a public IP address it returns only the countryname in the trap.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, the field [Origin] always returns the IP as "0", but I could really work with the second sub-field "hostname":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Origin: (IP: 0; hostname: SMS; repetitions: 1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to put&amp;nbsp;these&amp;nbsp;sub-fields in the trap using some variation of the notation [&amp;lt;field&amp;gt;]?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The alternative would be to create a script to filter the event output and send these traps, but I'd rather not have to install scripts every time I need to set these up.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2017 14:19:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5565#M100975</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2017-08-23T14:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Event Fields in automatic reaction on R80.10?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5566#M100976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pedro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you ever get anywhere with this? I have the same requirement...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luke&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2018 15:22:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5566#M100976</guid>
      <dc:creator>Luke_Bourike</dc:creator>
      <dc:date>2018-05-29T15:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Event Fields in automatic reaction on R80.10?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5567#M100977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Luke,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, I never solved this. I am currently experimenting with a third party SIEM, but it would be great to make this work correctly with SmartEvent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2018 17:11:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5567#M100977</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-04T17:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Event Fields in automatic reaction on R80.10?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5568#M100978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/41651"&gt;Kfir Dadosh&lt;/A&gt;‌ any thoughts on this one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2018 05:04:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-to-use-Event-Fields-in-automatic-reaction-on-R80-10/m-p/5568#M100978</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-05T05:04:41Z</dc:date>
    </item>
  </channel>
</rss>

