<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filtering tcp packet out of state in views/reports in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/189133#M34788</link>
    <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I'd like to ask you regarding the filtering out dropped communication which is out of state. Im trying to make custom view where I can check number of TCP out of state logs over some period of time. I got in to the point where Im seeing drops in my view but can not find any way how to filter out only out of state packets. I've tried to type "First packet isn't SYN" or "TCP packet out of state" in to the search bar but no results. When I use same query for standard logs I can filter out out of state logs.&lt;/P&gt;&lt;P&gt;Thanks for help&lt;/P&gt;&lt;P&gt;R80.40,&lt;/P&gt;&lt;P&gt;Appliances 6000&lt;/P&gt;&lt;P&gt;TAKE 197&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2023 10:26:29 GMT</pubDate>
    <dc:creator>Sajgon107</dc:creator>
    <dc:date>2023-08-10T10:26:29Z</dc:date>
    <item>
      <title>Filtering tcp packet out of state in views/reports</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/189133#M34788</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I'd like to ask you regarding the filtering out dropped communication which is out of state. Im trying to make custom view where I can check number of TCP out of state logs over some period of time. I got in to the point where Im seeing drops in my view but can not find any way how to filter out only out of state packets. I've tried to type "First packet isn't SYN" or "TCP packet out of state" in to the search bar but no results. When I use same query for standard logs I can filter out out of state logs.&lt;/P&gt;&lt;P&gt;Thanks for help&lt;/P&gt;&lt;P&gt;R80.40,&lt;/P&gt;&lt;P&gt;Appliances 6000&lt;/P&gt;&lt;P&gt;TAKE 197&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 10:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/189133#M34788</guid>
      <dc:creator>Sajgon107</dc:creator>
      <dc:date>2023-08-10T10:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering tcp packet out of state in views/reports</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/190399#M35137</link>
      <description>&lt;P&gt;Not really sure what you're showing a screenshot of here.&lt;BR /&gt;In any case, not every field in a log is indexed, thus you cannot search or create reports on it.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 22:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/190399#M35137</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-23T22:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering tcp packet out of state in views/reports</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/214186#M40883</link>
      <description>&lt;P&gt;I have been asked to provide the same type of reports for TCP out of sequence fields recently and believe i have the same question as the original requester here.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Within Smartconsole itself, you can add in the columns of "TCP packet out of state" and "TCP Flags" for log searches.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even the problem here with this raw output is that you can't export the CSV as it directs you to use SmartView.&amp;nbsp; &amp;nbsp; On Smartview, these fields are not selectable (note:&amp;nbsp; &amp;nbsp;I have add success with 'tcp_flags:" with an exact flag; not wildcard" and a raw search of&amp;nbsp;"First packet isn't SYN" but not with 'tcp_packet_out_of_state' field).&lt;/P&gt;
&lt;P&gt;In regards to whether the log field is indexed, it looks like both the 'tcp_flag' and 'tcp_packet_out_of_state' fields are indexed per this SK (&lt;A href="https://support.checkpoint.com/results/sk/sk144192" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk144192&lt;/A&gt;).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any possibility for a user to add these two fields to use for a custom report or view?&amp;nbsp; &amp;nbsp; If so, is there any SK or guide i can reference?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 14:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/214186#M40883</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-05-14T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering tcp packet out of state in views/reports</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/214239#M40893</link>
      <description>&lt;P&gt;If the fields aren't available with SmartView, then it's probably an RFE to get this functionality.&lt;BR /&gt;However, you can also use either fw log or CpLogFilePrint to do a raw ASCII dump of the logs and grep for the relevant lines.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 21:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Filtering-tcp-packet-out-of-state-in-views-reports/m-p/214239#M40893</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-14T21:56:42Z</dc:date>
    </item>
  </channel>
</rss>

