<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPNotEnoughDataForRuleMatch in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/198956#M37258</link>
    <description>&lt;P&gt;I am not sure these kinds of logs can be disabled. Are they causing you an inconvenience?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 08:42:30 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-11-27T08:42:30Z</dc:date>
    <item>
      <title>CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/198942#M37254</link>
      <description>&lt;P&gt;Since we upgraded to R81.10 we've noticed that the introduction of the "CPNotEnoughDataForRuleMatch" log entry due to&amp;nbsp;&lt;SPAN&gt;sk113479, and it is now populating our logs with extra events that would otherwise not have any log entry created at all - either for a Security policy rule that is set to Track None, and/or for traffic passing through the separate Application &amp;amp; URL filtering policy layer where the connection is dropped by the client or server during a state of "possible match".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question: is it possible to disable the creation of the "CPNotEnoughDataForRuleMatch" log entries for possible rule matches in 81.10?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 05:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/198942#M37254</guid>
      <dc:creator>meliux</dc:creator>
      <dc:date>2023-11-27T05:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/198956#M37258</link>
      <description>&lt;P&gt;I am not sure these kinds of logs can be disabled. Are they causing you an inconvenience?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 08:42:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/198956#M37258</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-11-27T08:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199029#M37281</link>
      <description>&lt;P&gt;The reason you're probably seeing this is because one or more rules are possible matches for the traffic (based on source/destination/service) that contain App Control/URLF objects in the Services column.&lt;BR /&gt;You may need to create an explicit rule near the top of the rulebase to permit this traffic without logging.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:21:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199029#M37281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-27T14:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199030#M37282</link>
      <description>&lt;P&gt;Its essentially a way of telling you that 3-way handshake is not completing properly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:29:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199030#M37282</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-27T14:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199088#M37297</link>
      <description>&lt;P&gt;yeah, it is inconvenient because all our logs are being exported out to Splunk which has a real cost associated with it... was hoping these unnecessary logs could be removed prior to any manual filtering in the log exporter etc. We're talking millions of additional log entries that weren't there prior to 81.10.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 23:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199088#M37297</guid>
      <dc:creator>meliux</dc:creator>
      <dc:date>2023-11-27T23:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199091#M37298</link>
      <description>&lt;P&gt;yep.... so can these be ignored/unlogged?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 23:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199091#M37298</guid>
      <dc:creator>meliux</dc:creator>
      <dc:date>2023-11-27T23:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199095#M37300</link>
      <description>&lt;P&gt;Thats what TAC told me couple of years back, correct.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 23:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199095#M37300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-27T23:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199538#M37416</link>
      <description>&lt;P&gt;Yes, that's the only workaround that it worked for me (sometimes not)&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 23:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199538#M37416</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-12-01T23:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199539#M37417</link>
      <description>&lt;P&gt;If multiple ordered layers are used, make sure to check each layer to ensure the rule that matches the relevant traffic does not include logging.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 23:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/199539#M37417</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-01T23:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/208727#M39521</link>
      <description>&lt;P&gt;Should the URL Filtering /App Control be inside the Internet Layer or not?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 09:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/208727#M39521</guid>
      <dc:creator>rzsuarez</dc:creator>
      <dc:date>2024-03-14T09:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: CPNotEnoughDataForRuleMatch</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/208782#M39534</link>
      <description>&lt;P&gt;Depends on how your layers are constructed.&lt;BR /&gt;A top-level "Firewall Only" layer with one or more inline layers with App Control/URL Filtering enabled is an approach I've used/recommended, particularly for customer moving from R7x releases where there were separate policies (layers) for Firewall and App Control/URL Filtering.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 15:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPNotEnoughDataForRuleMatch/m-p/208782#M39534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-14T15:19:54Z</dc:date>
    </item>
  </channel>
</rss>

