<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: smartview monitor and smartview logs didnt match in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189123#M34786</link>
    <description>&lt;P&gt;So, my understanding is, you cannot find logs for certain connections. Do you log all rules?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2023 07:56:05 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-08-10T07:56:05Z</dc:date>
    <item>
      <title>smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/188730#M34746</link>
      <description>&lt;P&gt;Hello Guys, I have a question about our monitoring tools, on smartview I am seeing a huge spike on SRC and DEST. however, when I check on smartview logs I didnt see the logs for it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;Smartview monitor shows 60Gbps of traffic spike for SRC A and DEST B.&lt;/P&gt;&lt;P&gt;when I review the logs on smartview logs this connection didnt show up.&lt;/P&gt;&lt;P&gt;Note: we have a specific rule that allows the connection.&lt;/P&gt;&lt;P&gt;Any reasons you know why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 07:26:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/188730#M34746</guid>
      <dc:creator>cathychan</dc:creator>
      <dc:date>2023-08-07T07:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189012#M34773</link>
      <description>&lt;P&gt;How did you search?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 05:07:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189012#M34773</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-09T05:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189013#M34774</link>
      <description>&lt;P&gt;It seems to me, you are missing a font or two, so they do not render.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 05:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189013#M34774</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-09T05:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189121#M34784</link>
      <description>&lt;P&gt;thank you Val for response, can you share what do you mean by Font &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; Im sorry I am new.. If you mean filter.. what I did is&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;origin: FWCluster&lt;/P&gt;&lt;P&gt;Source: SOURCEIP&lt;/P&gt;&lt;P&gt;port: 2049&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check on the statistics no logs for the destination I am looking to but I can definitely see it on monitor and also on packet capture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 07:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189121#M34784</guid>
      <dc:creator>cathychan</dc:creator>
      <dc:date>2023-08-10T07:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189122#M34785</link>
      <description>&lt;P&gt;Sorry, I though I was answering a different thread, disregard the fonts &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 07:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189122#M34785</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-10T07:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189123#M34786</link>
      <description>&lt;P&gt;So, my understanding is, you cannot find logs for certain connections. Do you log all rules?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 07:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189123#M34786</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-10T07:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189124#M34787</link>
      <description>&lt;P&gt;yes we do log all rules.. for some reason only this is not logged&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 08:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/189124#M34787</guid>
      <dc:creator>cathychan</dc:creator>
      <dc:date>2023-08-10T08:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: smartview monitor and smartview logs didnt match</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/190383#M35131</link>
      <description>&lt;P&gt;Is it a continually active connection (i.e. no TCP FIN/RST) or one that terminates/re-establishes?&lt;BR /&gt;If it's continually active, then you will only find a single log entry for the original connection establishment with the bytes updated on that log entry.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 21:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smartview-monitor-and-smartview-logs-didnt-match/m-p/190383#M35131</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-23T21:12:58Z</dc:date>
    </item>
  </channel>
</rss>

