<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log Actions - Explanation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139563#M21308</link>
    <description>&lt;P&gt;Does anyone have a better reference or does anyone have the knowledge to explain what the various actions in the log_action field actually mean? Also what blade generated it and what is the expected outcome?&lt;/P&gt;&lt;P&gt;For example Drop is generated by Firewall - and the session is finished with a silent drop [timeout].&lt;/P&gt;&lt;TABLE width="420"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;int&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Action of matched rule&lt;BR /&gt;Possible values:&lt;BR /&gt;0 - Drop&lt;BR /&gt;1 - Reject&lt;BR /&gt;2 - Accept&lt;BR /&gt;3 - Encrypt&lt;BR /&gt;4 - Decrypt&lt;BR /&gt;17 - Authorize&lt;BR /&gt;18 - Deauthorize&lt;BR /&gt;30 - Bypass&lt;BR /&gt;33 - Block&lt;BR /&gt;34 - Detect&lt;BR /&gt;39 - Do not send&lt;BR /&gt;43 - Allow&lt;BR /&gt;46 - Ask User&lt;BR /&gt;61 - Extract&lt;BR /&gt;&lt;BR /&gt;Note: This field is not mandatory to every log&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference:&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144192" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144192&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jan 2022 11:10:31 GMT</pubDate>
    <dc:creator>cezar_varlan1</dc:creator>
    <dc:date>2022-01-26T11:10:31Z</dc:date>
    <item>
      <title>Log Actions - Explanation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139563#M21308</link>
      <description>&lt;P&gt;Does anyone have a better reference or does anyone have the knowledge to explain what the various actions in the log_action field actually mean? Also what blade generated it and what is the expected outcome?&lt;/P&gt;&lt;P&gt;For example Drop is generated by Firewall - and the session is finished with a silent drop [timeout].&lt;/P&gt;&lt;TABLE width="420"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;int&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Action of matched rule&lt;BR /&gt;Possible values:&lt;BR /&gt;0 - Drop&lt;BR /&gt;1 - Reject&lt;BR /&gt;2 - Accept&lt;BR /&gt;3 - Encrypt&lt;BR /&gt;4 - Decrypt&lt;BR /&gt;17 - Authorize&lt;BR /&gt;18 - Deauthorize&lt;BR /&gt;30 - Bypass&lt;BR /&gt;33 - Block&lt;BR /&gt;34 - Detect&lt;BR /&gt;39 - Do not send&lt;BR /&gt;43 - Allow&lt;BR /&gt;46 - Ask User&lt;BR /&gt;61 - Extract&lt;BR /&gt;&lt;BR /&gt;Note: This field is not mandatory to every log&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference:&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144192" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144192&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 11:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139563#M21308</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2022-01-26T11:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Log Actions - Explanation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139575#M21314</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=Basic&amp;amp;product=SmartEvent" target="_blank"&gt;sk122323: Log Exporter - Check Point Log Export&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 11:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139575#M21314</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-26T11:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Log Actions - Explanation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139657#M21339</link>
      <description>&lt;P&gt;Got myself caught up in a cycling reference back to my own SK -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp; that article is not what I am asking. I do know how to extract the blade in the logs. But this implies the log happened, I am trying to create a dictionary and attach this to a splunk dashboard that I will publish to the rest of the IT organization so people can do a self-service lookup instead of a specific search in firewall logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 06:32:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139657#M21339</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2022-01-27T06:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Log Actions - Explanation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139793#M21372</link>
      <description>&lt;P&gt;Good luck with your work !&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 07:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Actions-Explanation/m-p/139793#M21372</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-28T07:54:06Z</dc:date>
    </item>
  </channel>
</rss>

